Blog/vulnerabilities
vulnerabilities

Rockwell Automation ControlFLASH

September 3, 2026·Source: CISA
0 comments

TL;DR

View CSAF Summary Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level. The following versions of Rockwell Automation ControlFLASH are affected: ControlFLASH <=V15.07 (CVE-2026-12663) CVSS Vendor Equipment Vulnerabilities

v3 7.3 Rockwell Automation Rockwell Automation ControlFLASH Missing Authentication for Critical Function

Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-12663 A security issue exists within ControlFLASH, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level. View CVE Details Affected Products Rockwell Automation ControlFLASH Vendor: Rockwell Automation Product Version: Rockwell Automation ControlFLASH: <=V15.07 Product Status: known_affected Remediations Mitigation Rockwell Automation has corrected this issue in software version 15.08, and encourages all users to update to the newest version. Mitigation Users of the affected software who are not able to upgrade to one of the corrected versions should implement the following mitigation:  To protect the files, do the following steps to remove the Everyone group:  Right-click the C:\Program Files (x86)\ControlFLASH\0001 folder, and then select Properties.  In the 0001 Properties dialog, select the Security tab, and then select Edit.  In the Permissions for 0001 dialog, in Group or user names, select Everyone, and then select Remove.  Select OK. Mitigation If the mitigation above cannot be implemented, Rockwell Automation recommends foll

What Happened

Rockwell Automation ControlFLASH, reported by CISA.

View CSAF Summary Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level. The following versions of Rockwell Automation ControlFLASH are affected: ControlFLASH <=V15.07 (CVE-2026-12663) CVSS Vendor Equipment Vulnerabilities

v3 7.3 Rockwell Automation Rockwell Automation ControlFLASH Missing Authentication for Critical Function

Background Critical Infrastructure Sectors: Critical Manufacturing, Energy, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-12663 A security issue exists within ControlFLASH, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level. View CVE Details Affected Products Rockwell Automation ControlFLASH Vendor: Rockwell Automation Product Version: Rockwell Automation ControlFLASH: <=V15.07 Product Status: known_affected Remediations Mitigation Rockwell Automation has corrected this issue in software version 15.08, and encourages all users to update to the newest version. Mitigation Users of the affected software who are not able to upgrade to one of the corrected versions should implement the following mitigation:  To protect the files, do the following steps to remove the Everyone group:  Right-click the C:\Program Files (x86)\ControlFLASH\0001 folder, and then select Properties.  In the 0001 Properties dialog, select the Security tab, and then select Edit.  In the Permissions for 0001 dialog, in Group or user names, select Everyone, and then select Remove.  Select OK. Mitigation If the mitigation above cannot be implemented, Rockwell Automation recommends foll

For the full technical details, see the original report.

Why It Matters for Businesses

This development could affect organizations that rely on the impacted technologies or services. Unpatched systems, misconfigured infrastructure, or lack of monitoring can leave businesses exposed to exploitation, data breaches, and regulatory penalties.

How to Check Your Exposure

Run a free scan on NEL Professional's Cyber Risk Scanner to check whether your domain is affected. The scan covers SSL/TLS, security headers, DNS configuration, email authentication, and more across 16 modules.

Check Your Domain Security

Mitigation Steps

  • Patch immediately, Apply vendor patches or updates as soon as they are available.
  • Review configurations, Check firewall rules, access controls, and security headers.
  • Monitor logs, Watch for indicators of compromise (IOCs) related to this threat.
  • Update security policies, Ensure incident response plans cover this type of threat.
  • Run a security scan, Use automated tools to verify your exposure.

Need Expert Help?

If your organization needs help assessing or remediating this issue, hire a verified cybersecurity specialist through NEL Professionals.

Need More Scan Credits?

Get up to 100 scans or unlimited lifetime access starting at $15.

View Plans →

Comments (0)

No comments yet. Be the first to comment!

← Back to Blog