CVE-2026-11317: Rockwell Automation Compactlogix, Controllogix
High severity, CVSS 8.7. EPSS: 0.3% chance of exploitation in the next 30 days.
A denial of service security issue exists in the affected product. The security issue stems from a fault occurring when a crafted CIP message is sent. Devices with less memory are more likely to be affected. This can result in a major nonrecoverable fault (MNRF). A program download is required to recover.
Affected products
- Rockwell Automation Compactlogix, Controllogix: before 34.016 (fixed in 34.016); before 35.015 (fixed in 35.015); before 36.012 (fixed in 36.012)
Published 2026-06-16. Last modified 2026-06-17.