CVE-2026-9636 Details
Description
A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation handling. The security issue stems from the controller failing to properly reject certificates signed by an intermediate certificate that has been revoked via a Certificate Revocation List (CRL). This could allow a network-based attacker to establish a connection using a certificate that should be untrusted, potentially bypassing CIP Security protections.
A vulnerability exists in Rockwell Automation's CompactLogix 5380, ControlLogix 5580, and EN4 communication modules regarding the handling of Certificate Revocation Lists (CRLs) in CIP Security. The issue arises because the controllers do not properly reject certificates signed by an intermediate certificate that has been revoked. This flaw could enable a network-based attacker to establish a connection using a certificate that should be considered untrusted, potentially bypassing CIP Security protections. The vulnerability affects users with the CRL feature enabled and using intermediary certificates.
Users can upgrade to ControlLogix 5580 version 38.011, CompactLogix 5380 version 38.011, or 1756-EN4TR version 8.001. For those unable to upgrade, Rockwell Automation recommends following their security best practices.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1788.html | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-299 | Improper Check for Certificate Revocation | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | New CVE Received | [email protected] |
| Jul 14, 2026 | CVE Modified | CISA-ADP |