CVE-2026-9653 HIGH

CVE-2026-9653: 1756-EN2, 1756-EN3, and 1756-ENBT - Denial of Service via CIP Connection ID

Vendor Rockwell Automation
Product 1756-EN2, 1756-EN3
Weakness CWE-354
Published July 14, 2026
Last update July 14, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An attacker on the network can exploit this by sending crafted packets to continuously disrupt device connections, though device connections will recover immediately after.

Key dates

02Disclosure timeline

July 14, 2026 CVE published
July 14, 2026 Record updated