← Back to Feed

Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module

CVE-2026-9636

July 30, 2026 · CISA (US-CERT) · Severity: CRITICAL

A security issue exists in Rockwell Automation CompactLogix 5380, ControlLogix 5580, and EN4TR communication modules related to CIP Security certificate revocation handling. The controller fails to properly reject certificates signed by an intermediate certificate that has been revoked via a CRL, potentially allowing a network-based attacker to establish an untrusted connection and cause a denial-of-service condition.

Key Takeaways

  • The vulnerability involves improper certificate revocation checking in CIP Security.
  • An attacker could bypass CIP Security protections using a revoked certificate.
  • Successful exploitation could allow a network-based attacker to cause a denial-of-service condition.
☕ Buy a Coffee