Executive Summary

CVE-2026-9637 affects the Rockwell Automation Logix platform across ControlLogix 5580, CompactLogix 5380, and GuardLogix 5580 controllers on firmware V33 and earlier as well as the V34.011 through V36.012 branches. Because GuardLogix is a safety-rated line, the exposure reaches both process control and the safety instrumented functions that protect personnel and equipment.

Technical Exposure Breakdown

The affected controllers are the core of a large share of deployed Rockwell architectures in North American manufacturing, water, and energy environments. The grounding data confirms the affected firmware bands: V33 and earlier, V34.011 through V34.014, V35.011 through V35.013, and V36.012 and earlier within the V36 branch. No CVSS score and no patch status are available at this time, and this analysis does not assign either.

Logix controllers communicate over EtherNet/IP and CIP. That protocol stack is the primary attack surface for controller-class flaws, and it is reachable from any device on the same industrial segment that can route CIP traffic. In practice that means an adversary who has already established a foothold on the OT network, or who is bridging from a compromised engineering workstation, is positioned to reach the controller directly. The presence of GuardLogix in the affected list is the detail that should drive triage priority. A safety controller entering a fault or losing determinism is not an availability inconvenience. It can force a safety trip or, worse, mask a condition the safety function was installed to detect.

Without a published CVSS vector or a detailed mechanism in the source, the responsible posture is to treat this as a controller-reachable condition affecting a broad installed base and to plan around the network path rather than the exploit detail.

OT Impact and Compliance Risk

The physical outcomes for a Logix-class fault are well understood. A controller that faults or restarts drops its program scan, de-energizes or freezes outputs depending on configured fault behavior, and interrupts the deterministic loop that regulates pumps, valves, motors, and safety interlocks. In a GuardLogix deployment the safety task is co-resident, so degradation touches the layer of last resort.

For regulated operators the compliance exposure is concrete. Under NERC CIP, controllers in a bulk electric system environment fall within the electronic security perimeter and any patch or configuration change enters CIP-010 change management and CIP-007 patch evaluation timelines. IEC 62443 zone and conduit segmentation is the primary structural defense here, and a flat network that lets CIP traffic reach a GuardLogix from a business subnet is a 62443 finding independent of this CVE. Pipeline operators under TSA SD-02C must account for this in their critical cyber system inventory and remediation plans. Water and wastewater utilities operating Logix under AWIA 2018 risk and resilience obligations should log the exposure against their assessment.

Compensating Controls

Do not treat active vulnerability scanning as a discovery step here. EtherNet/IP and CIP stacks on production controllers have a documented history of faulting under aggressive probing, and scanning a live GuardLogix can trigger the exact safety condition you are trying to avoid. Use passive traffic inspection and configuration inventory to identify affected firmware bands.

BreachSpider Intel

BreachSpider tracks CVE-2026-9637 and the broader Rockwell Logix advisory chain, and continuously monitors for patch publication and exploitation signal so OT teams can act on verified changes rather than speculation.