Rockwell Automation Historian ME
2026-09-01T19:23:20Z•d58dbfd3f23563f49f12a5404a8abfc295445fe99fac653d313c505810df6f31
CVE-2021-42260CVE-2025-12768CVE-2026-12661CVE-2026-16675CVE-2026-76943CVE-2026-78037CVE-2026-78239CVE-2026-9621CVE-2026-9622CVE-2026-9624CVE-2026-9625CVE-2026-9633CVE-2026-9634CVE-2026-9637CISA ICS advisoryCompactLogixControlLogixDLL hijackingFactoryTalkGuardLogixHistorian MEOS command injectionOT securityRSLinx ClassicRockwell AutomationXiiaozet LK100Wauthentication bypassbuffer overflowcritical manufacturingdenial of serviceindustrial control systemsmemory corruptionprivilege escalationremote code execution
What happened
CISA ICS advisories dated September 1, 2026 cover multiple Rockwell Automation industrial products and Xiiaozet LK100W. Reported issues include remote code execution, privilege escalation, denial of service, memory corruption, DLL hijacking, authentication bypass, and OS command injection. Affected products include Rockwell Historian ME, ControlLogix and related Logix platforms, FactoryTalk Activation Manager, Redundancy Module Configuration Tool, RSLinx Classic, and Xiiaozet LK100W. Organizations should identify affected versions, apply vendor fixes or mitigations, and restrict exposure of OT
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ics_advisories
- Record identifier
- d58dbfd3f23563f49f12a5404a8abfc295445fe99fac653d313c505810df6f31
- Enrichment time
- 2026-09-01T19:23:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.