High‑Severity DoS Vulnerability (CVE‑2026‑9653) Impacts Rockwell Automation 1756‑EN2/EN3/ENBT Modules
What It Is — A CVE‑2026‑9653 vulnerability in Rockwell Automation 1756‑EN2, EN3, and ENBT communication modules allows an attacker to send crafted CIP Implicit Connection packets that trigger a denial‑of‑service condition. The devices recover automatically once the attack stops, but the disruption can affect critical manufacturing processes.
Exploitability — CVSS v3.1 base score 7.5 (High). The issue is publicly disclosed by CISA; no public exploit code is known, but the attack vector is network‑based and requires the adversary to be on the same LAN or have access to the control‑system network.
Affected Products — Rockwell Automation 1756‑EN2 (≤ V12.001), 1756‑EN3 (≤ V12.001), and 1756‑ENBT (V6.006).
Why It Matters for Compliance & Audit Readiness
- SOC 2 Availability (CC6.1) and System Monitoring (CC7.1) controls demand documented evidence that critical OT devices are patched and that service interruptions are detected in real time.
- Continuous control monitoring of firmware versions and patch status provides audit‑ready proof that you are mitigating known vulnerabilities.
- Enterprise buyers increasingly request a defensible remediation process for OT assets as part of their vendor‑risk assessments.
Recommended Actions
- Inventory all 1756‑EN2/EN3/ENBT modules and verify firmware versions against the advisory.
- Patch the devices with Rockwell’s fix as soon as it is released; if patching is delayed, apply network segmentation and IDS signatures to block malformed CIP packets.
- Map the remediation to SOC 2 CC6.1/CC7.1 controls, capture patch‑status evidence, and integrate the data into your continuous‑compliance dashboard.
Source: CISA Advisory – ICSA‑26‑197‑02