CVE-2026-84235

N/A

A denial-of-service security issue exists in the affected product. The security issue stems from a crafted CIP packet being sent crashing the module. The device requires a restart to recover.

Affects 0 products across 1 vendor.

CVSS v48.7
EPSS0.4%
Percentile35th
PatchUnknown
CWE Weakness Definitions
CWE-400: Uncontrolled Resource Consumption (DoS)

Software does not properly limit resource usage, allowing an attacker to exhaust CPU, memory, disk, or bandwidth.

Related Attack Patterns (CAPEC)
CAPEC-147 XML Ping of the Death
via CWE-400
CAPEC-492 Regular Expression Exponential Blowup
via CWE-400
CAPEC-227 Sustained Client Engagement
via CWE-400

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

A unscored severity vulnerability (CVE-2026-84235) affects the target system. A denial-of-service security issue exists in the affected product. The security issue stems from a crafted CIP packet being sent crashing the module. The device requires a restart to recover.

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-84235?
A unscored severity vulnerability (CVE-2026-84235) affects the target system. A denial-of-service security issue exists in the affected product. The security issue stems from a crafted CIP packet being sent crashing the module. The device requires a restart to recover.
Is CVE-2026-84235 actively exploited?
No confirmed active exploitation of CVE-2026-84235 as of 2026-09-02.
How do I remediate CVE-2026-84235?
Apply vendor patches for CVE-2026-84235. Monitor Rockwell Automation advisories.
What systems are affected by CVE-2026-84235?
CVE-2026-84235 affects: Rockwell Automation.
Vulnerability Details
CVE IDCVE-2026-84235
Published2026-09-01
Last Modified2026-09-01
ICS Relevance70%
Weakness (CWE)
SourceNVD
Official Description

A denial-of-service security issue exists in the affected product. The security issue stems from a crafted CIP packet being sent crashing the module. The device requires a restart to recover.

Source: NIST NVD / MITRE CVE Database

Affected Products
VendorProductFixed Version
Rockwell Automation — —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 27 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
Related CVEs affecting Rockwell Automation
CVE-2017-16740 10.0 A Buffer Overflow issue was discovered in Rockwell Automation Allen-Bradley M... CVE-2012-4715 10.0 Buffer overflow in LogReceiver.exe in Rockwell Automation RSLinx Enterprise C... CVE-2009-3739 10.0 Multiple unspecified vulnerabilities on the Rockwell Automation AB Micrologix... CVE-2016-9343 10.0 An issue was discovered in Rockwell Automation Logix5000 Programmable Automat... CVE-2020-14516 10.0 In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.1...
View all Rockwell Automation CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider tracks 366,000+ CVEs and matches them to your ICS/OT assets by exact version, with AI analysis, NERC CIP mapping, and vendor PSIRT contacts.

Create a free account →