Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Rockwell Vulnerability Allowing Remote ICS Hacking Exploited in Attacks
    Cybersecurity

    Rockwell Vulnerability Allowing Remote ICS Hacking Exploited in Attacks

    adminBy adminMarch 8, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Rockwell Automation vulnerabilities
    Share
    Facebook Twitter LinkedIn Pinterest Email

    An old vulnerability affecting industrial control system (ICS) products from Rockwell Automation has been exploited in attacks, according to the vendor and the cybersecurity agency CISA.

    CISA added the flaw, tracked as CVE-2021-22681, to its Known Exploited Vulnerabilities (KEV) catalog on Thursday, instructing federal agencies to address it by March 26. 

    The security hole affects the Studio 5000 Logix Designer software and several Logix programmable logic controllers (PLCs), including CompactLogix, ControlLogix, DriveLogix, FlexLogix, GuardLogix, and SoftLogix devices.

    CVE-2021-22681 was disclosed in February 2021, when the vendor announced mitigations and credited Soonchunhyang University in South Korea, Kaspersky, and Claroty for reporting it. Claroty said at the time that it had reported the issue to Rockwell in 2019.

    The vulnerability, related to an insufficiently protected cryptographic key, could allow a remote, unauthenticated attacker to bypass verification and connect to a targeted controller by mimicking an engineering workstation.

    In a real-world industrial environment, the vulnerability could allow remote attackers to manipulate PLC logic and disrupt manufacturing processes, or even cause physical damage to equipment.  

    Advertisement. Scroll to continue reading.

    Rockwell updated its initial advisory on Thursday to mention in-the-wild exploitation of CVE-2021-22681, but the company has not shared any information about the attacks.

    SecurityWeek has reached out to Rockwell for comment and will update this article if the company responds.

    A Shodan search currently shows nearly 6,000 internet-exposed Rockwell devices, but it’s unclear how many may be affected by CVE-2021-22681.

    It’s worth noting that Rockwell issued a security notice in 2024, urging customers to ensure their ICS devices are not connected to the internet. One of the vulnerabilities highlighted in that alert was CVE-2021-22681, which indicates that the vendor did not rule out malicious exploitation. 

    In 2023, Rockwell and CISA warned that an unnamed APT had developed an exploit for a different Rockwell controller vulnerability (CVE-2023-3595), which could be exploited to cause disruption or destruction, but there had been no evidence of actual attacks. 

    Currently, CVE-2021-22681 is the only Rockwell product vulnerability in CISA’s KEV catalog. 

    Related: 3 Threat Groups Started Targeting ICS/OT in 2025: Dragos

    Related: Honeywell, Researcher Clash Over Impact of Building Controller Vulnerability

    Related: Critical Flaws Exposed Gardyn Smart Gardens to Remote Hacking

    Allowing attacks Exploited hacking ICS Remote Rockwell vulnerability
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleWindows 11’s new feature will make it really easy to toggle dark mode
    Next Article AI agents: Powering Europe’s most ambitious startups
    admin
    • Website

    Related Posts

    Armadin secures $189.9 million to counter AI-driven cyber threats

    March 10, 2026

    APT28 hackers deploy customized variant of Covenant open-source tool

    March 10, 2026

    Cylake Raises $45 Million to Secure Organizations Barred From Cloud

    March 10, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Armadin secures $189.9 million to counter AI-driven cyber threats

    March 10, 2026

    How I Use My iPhone’s Focus Modes to Stop Getting Distracted at the Gym

    March 10, 2026

    APT28 hackers deploy customized variant of Covenant open-source tool

    March 10, 2026

    You Can Disavow Entire TLDs Like .XYZ With Domain Directive

    March 10, 2026
    Categories
    • Blogging (36)
    • Cybersecurity (695)
    • Privacy & Online Earning (97)
    • SEO & Digital Marketing (431)
    • Tech Tools & Mobile / Apps (860)
    • WiFi / Internet & Networking (114)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Armadin secures $189.9 million to counter AI-driven cyber threats

    March 10, 2026

    How I Use My iPhone’s Focus Modes to Stop Getting Distracted at the Gym

    March 10, 2026

    APT28 hackers deploy customized variant of Covenant open-source tool

    March 10, 2026
    Most Popular
    • Armadin secures $189.9 million to counter AI-driven cyber threats
    • How I Use My iPhone’s Focus Modes to Stop Getting Distracted at the Gym
    • APT28 hackers deploy customized variant of Covenant open-source tool
    • You Can Disavow Entire TLDs Like .XYZ With Domain Directive
    • Bentley turns Spanish mountain into bespoke luxury with Bentayga Artenara Edition
    • Cylake Raises $45 Million to Secure Organizations Barred From Cloud
    • AI assistants now equal 56% of global search engine volume: Study
    • Monster Hunter Now 116.0 APK Download by Niantic, Inc.
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.