Rockwell Automation ControlFLASH
September 3, 2026 · CISA (US-CERT) · Severity: CRITICAL
View CSAF Summary Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level. The following versions of Rockwell Automation ControlFLASH are affected: ControlFLASH <=V15.07 (CVE-2026-12663) CVSS Vendor Equipment Vulnerabilities v3 7.3 Rockwell Automation Rockwell Automation ControlFLASH Missing Authentication for Critical Function Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-12663 A security issue exists within ControlFLASH, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level. View CVE Details Affected Products Rockwell Automation ControlFLASH Vendor:Rockwell Automation Product Version:Rockwell Automation ControlFLASH: <=V15.07 Product Status:known_affected Remediations MitigationRockwell Automation has corrected this issue in software version 15.08, and encourages all users to update to the newest version. MitigationUsers of the affected software who are not able to upgrade to one of the corrected versions should implement the following mitigation: To protect the files, do the following steps to remove the Everyone group: Right-click the C:\Program Files (x86)\ControlFLASH\0001 folder, and then select Properties. In the 0001 Properties dialog, select the Security tab, and then select Edit. In the Permissions for 0001 dialog, in Group or user names, select Everyone, and then select Remove. Select OK. MitigationIf the mitigation above cannot be...
Key Takeaways
- CISA published an advisory for Rockwell Automation ControlFLASH urging users to apply vendor patches and mitigations.
- Organizations using Rockwell Automation ControlFLASH should review CISA's advisory and apply security updates promptly.
- Active exploitation of vulnerabilities in Rockwell Automation ControlFLASH has been reported, making patching urgent for affected organizations.