Denial‑of‑Service Vulnerability (CVE‑2026‑12659) in Rockwell Automation Flex 5000 Adapter Threatens Industrial Control Systems
What It Is — A double‑free flaw in Rockwell Automation Flex 5000 Adapter version 6.011 allows crafted CIP packets to trigger an exception that crashes the module, resulting in denial‑of‑service.
Exploitability — CVSS v3.1 base score 7.5 (High); the advisory confirms the vulnerability is exploitable, though no public exploit code has been released.
Affected Products — Rockwell Automation Flex 5000 Adapter 6.011 (industrial control system module).
Why It Matters for Compliance & Audit Readiness
- SOC 2 CC6.1 (System Operations) requires evidence that critical systems remain available; an unpatched DoS flaw directly undermines that control.
- Continuous monitoring of patch status and change‑management logs provides audit‑ready proof that remediation actions were taken promptly.
- Demonstrating a documented vulnerability‑management process satisfies the “Risk Management” principle for customers in regulated manufacturing sectors.
Recommended Actions —
- Upgrade all Flex 5000 Adapters to version 6.012 or later.
- Verify firmware versions via automated inventory and record the change in your configuration‑management system.
- Incorporate the patch‑status check into your continuous compliance monitoring platform to generate SOC 2 evidence.
- Apply Rockwell’s security‑best‑practice hardening guide for interim mitigation if upgrade is delayed.
Source: CISA Advisory – ICSA‑26‑197‑08