Executive Summary
CVE-2026-9622 is one of a cluster of memory corruption defects in Rockwell Automation RSLinx Classic involving integer overflow, integer underflow, and buffer copy operations that an attacker can drive into a denial-of-service condition. Because RSLinx Classic sits as the communication driver between engineering workstations and PLC-class controllers, loss of that service severs the operator and engineer view into the process while the physical plant continues to run blind.
Technical Exposure Breakdown
RSLinx Classic <=4.50 is the affected version range, per the grounding data. The vulnerability class here is arithmetic and copy handling failure. Integer overflow or wraparound and integer underflow conditions occur when a length or offset value crosses its numeric boundary and wraps to an unexpected value. When that corrupted value feeds a subsequent buffer copy, the software either reads or writes outside the intended memory region. In this advisory the documented outcome is a denial-of-service condition on the affected product, meaning the RSLinx service crashes or hangs rather than executing attacker code.
The attack vector matters more than the outcome label. RSLinx Classic listens for and parses industrial protocol traffic, and malformed packets crafted to trigger the wraparound arithmetic can reach the parser over the network. That means an adversary who already holds a foothold on a flat control network, or who can inject traffic onto the same segment as an engineering workstation, can knock the driver offline without touching the controller itself. The grouping of four related CVE identifiers under the same version ceiling suggests multiple discrete parsing paths were found by independent security research, not a single isolated bug.
A CVSS v3 base of 8.6 was assigned by the vendor for this equipment set. The grounding data does not specify a fix version or patch label, so treat patch availability as unconfirmed and do not assume an update resolves your specific installed build until you verify it against the advisory directly.
OT Impact and Compliance Risk
RSLinx Classic is frequently the single narrow channel through which HMI software, historians, and engineering tools reach a fleet of controllers. When that channel drops, operators lose live tags, alarm updates stall, and any batch or continuous process depending on supervisory coordination degrades. The controller keeps executing its last logic, which in some processes is worse than a clean stop because the process drifts with no human visibility.
Under IEC 62443 this is a zone and conduit integrity problem. RSLinx is a conduit-critical asset, and its exposure to arbitrary network peers violates the segmentation expectations of a properly designed system-under-consideration. NERC CIP registered entities should treat an internet-adjacent or shared-segment RSLinx host as a CIP-005 electronic security perimeter gap and a CIP-007 patch and ports-and-services finding. Pipeline operators under TSA SD-02C should map this against their required network segmentation and access control measures, since a DoS against the supervisory link is a direct hit on operational continuity objectives. Water utilities under AWIA 2018 should fold this into their risk and resilience assessment, given how many treatment sites run Rockwell communication stacks on aging workstations.
Compensating Controls
Do not attempt active vulnerability scanning to confirm exposure on live segments. Fuzzing or aggressive probing of a service with known parser defects can itself trigger the denial-of-service condition and brick or hang the communication driver you depend on. Enumerate passively.
- Isolate RSLinx Classic hosts behind a controller-aware firewall or data diode arrangement so only whitelisted engineering and HMI endpoints can reach the driver ports.
- Deploy a virtual patch at the segment boundary. A Suricata rule concept here inspects the relevant industrial protocol payloads for length fields that would wrap when combined with declared offsets, and drops or alerts on packets whose declared sizes are internally inconsistent before they reach the vulnerable parser.
- Restrict RSLinx to the minimum required protocol drivers and disable unused communication paths to shrink the reachable parser surface.
- Monitor for RSLinx service restarts and unexpected loss of controller connectivity as an early indicator of exploitation attempts.
- Once you confirm a validated fix version against the vendor advisory, schedule it into a maintenance window rather than pushing it live under process load.
BreachSpider Intel
Track CVE-2026-9622 and the related RSLinx Classic identifiers, along with exploitation signals and advisory revisions, through continuous monitoring at BreachSpider.