Rockwell Automation
The latest Rockwell Automation coverage — news, analysis, and updates from the WindowsNews.AI desk.
Your FactoryTalk Directory Might Be Trusting Forged Tokens — Here’s the Fix
July 21, 2026 — Rockwell Automation has disclosed a critical flaw in its FactoryTalk Services Platform (FTSP) that lets a low‑privilege user craft a malicious JSON Web Token and impersonate any...
Urgent: Rockwell Patches Three Studio 5000 Vulnerabilities—Check Your Version Now
Rockwell Automation has patched three vulnerabilities in its Studio 5000 Logix Designer software—the Windows-based engineering platform for Logix 5000 controllers—that could let a malicious ACD...
Malicious UDP Traffic Can Take Down Rockwell Ex I/O Adapters—Update to Firmware 3.012 Now
On July 14, 2026, Rockwell Automation disclosed a high-severity denial-of-service vulnerability in its 1718-AENTR and 1719-AENTR EtherNet/IP adapters. The flaw, CVE-2026-9140, allows an...
Rockwell’s 1734-OB8 Module Bug Forces Hardware Migration—Here’s Your Game Plan
Rockwell Automation disclosed on July 21, 2026, that its widely used 1734-OB8 eight-point digital output module contains a denial-of-service vulnerability—and there’s no firmware fix coming....
Urgent Update: Patch These Rockwell ControlLogix Modules Now, Or Face Network Disruption
Rockwell Automation and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) are urging immediate action after the disclosure of a high-severity denial-of-service vulnerability affecting...
Patch Now: Rockwell Arena Simulation Software Harbors Four Code-Execution Flaws
Rockwell Automation is urging users of its Arena discrete-event simulation software to apply an emergency update after security researcher Michael Heinzl uncovered four distinct memory-corruption...
FactoryTalk DataMosaix stored XSS could lead to account takeover — patch now
Rockwell Automation has issued an urgent patch for a stored cross-site scripting flaw in FactoryTalk DataMosaix Private Cloud that could let an attacker with high privileges inject malicious scripts...
Rockwell Automation Adapter Flaw Forces Manual Power Cycling – Windows-Based Control Systems at Risk
Rockwell Automation and the U.S. Cybersecurity and Infrastructure Security Agency on July 16, 2026 disclosed a high-severity denial-of-service vulnerability in the Flex 5000 Adapter that leaves...
Rockwell Logix Firmware Flaw Allows Instant Controller Crash—Patches Released
Rockwell Automation began pushing out firmware updates on July 14, 2026 for nearly its entire Logix controller line after its internal testing uncovered three separate vulnerabilities that let a...
Rockwell Adapter's Perfect 10 Vulnerability Puts Windows Networks on High Alert
Rockwell Automation's 1715-AENTR EtherNet/IP adapter has a flaw that lets attackers take full control without a password, and it carries a perfect CVSS score of 10. The bug, designated...
CISA Reissues Advisory as Authorization Bypass Vulnerability in Rockwell PavilionX Demands Immediate Patching
The U.S. Cybersecurity and Infrastructure Security Agency on June 16, 2026, republished a Rockwell Automation security advisory detailing a missing-authorization flaw in FactoryTalk Analytics...
Critical 9.4-Rated Bugs in Rockwell FLEX I/O Adapters Urge Immediate Patching
Two vulnerabilities in Rockwell Automation’s FLEX I/O EtherNet/IP adapters carry a CVSS score of 9.4, underscoring the severity of the flaws and the need for swift action. The U.S. Cybersecurity...