HomeIntelligenceBrief
VULNERABILITY BRIEF🟡 Medium Vulnerability

Improper Certificate Revocation Check (CVE‑2026‑9636) in Rockwell Automation CompactLogix & ControlLogix Modules Enables DoS

Rockwell Automation’s CompactLogix 5380, ControlLogix 5580 and EN4TR communication modules fail to reject certificates signed by a revoked intermediate, allowing a network‑based attacker to trigger denial‑of‑service. The flaw highlights a control‑mapping gap that must be documented for SOC 2 audit readiness.

LiveThreat™ Intelligence · 📅 July 30, 2026· 📰 cisa.gov
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
5 recommended
📰
Source
cisa.gov

Improper Certificate Revocation Check (CVE‑2026‑9636) in Rockwell Automation CompactLogix & ControlLogix Modules Enables DoS

What It Is – A vulnerability in Rockwell Automation’s CompactLogix 5380, ControlLogix 5580 and EN4TR communication modules (CVE‑2026‑9636) causes the controller to ignore revoked intermediate certificates. An attacker who can present such a certificate can force a denial‑of‑service condition.

Exploitability – No public exploit code has been released, but the advisory notes that network‑based attackers can reliably trigger the flaw. CVSS v3 base score 5.9 (Moderate).

Affected Products – Rockwell Automation CompactLogix 5380, ControlLogix 5580, GuardLogix 5580, Compact GuardLogix 5380, and EN4TR V6.001/V7.001 modules (firmware versions V36‑V37).

Why It Matters for Compliance & Audit Readiness

  • Control‑mapping: SOC 2 CC6.1 (system operations) and CC6.2 (change management) require documented, enforceable certificate‑validation processes; this flaw shows a gap that must be mapped and remediated.
  • Continuous evidence: Demonstrating that CRL checks are enforced in real‑time provides audit‑ready evidence and reduces the risk of service‑disruption findings during a SOC 2 audit.
  • Due‑diligence for third‑party risk: Many manufacturers rely on Rockwell controllers as a critical component of their supply chain; proving that you’ve validated and patched these devices is essential for vendor‑risk programs.

Recommended Actions

  • Inventory all Rockwell CompactLogix/ControlLogix/EN4TR devices and confirm firmware version.
  • Apply the vendor‑released patch that corrects the certificate‑revocation handling (or upgrade to a version > V37).
  • Update your SOC 2 control map to include “Certificate Revocation List verification” under system operations.
  • Capture remediation evidence (patch logs, configuration snapshots) in a centralized compliance repository.
  • Enable continuous monitoring of certificate validation failures and feed alerts into your audit‑readiness dashboard.

Source: CISA Advisory – ICSA‑26‑211‑05

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-05

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →