SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-9625

HIGH · CVSS 8.7 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

RSLinx® Classic is vulnerable to a denial-of-service attack due to the processing of oversized embedded message requests in crafted CIP packets, which can lead to a service crash. This vulnerability has a high severity rating (CVSS 8.7) and requires a manual restart of the service for recovery. Organizations using RSLinx® Classic should prioritize addressing this issue to prevent potential disruptions in service availability.

CVE
CVE-2026-9625
Severity
HIGH
CVSS
8.7
EPSS
0.31%

Original NVD Description

A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet with an oversized embedded message request can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover.