CISA published an advisory regarding a denial-of-service vulnerability (CVE-2021-42260) affecting multiple Rockwell Automation programmable logic controllers including ControlLogix 5580, GuardLogix 5580, CompactLogix 5380, Compact GuardLogix 5380, and CompactLogix 5480. The vulnerability is classified as CWE-835 (Loop with Unreachable Exit Condition / Infinite Loop) and can be triggered by sending corrupt crafted data to the affected devices. Successful exploitation can cause a major nonrecoverable fault (MNRF), requiring a program download for safety controllers or a stage 2 reset for non-safety controllers. The CVSS v3.1 base score is 7.5 (HIGH) and CVSS v4.0 base score is 8.7 (HIGH), with the attack vector being network-based, requiring no authentication or user interaction. Affected firmware versions are below 34.015, 35.014, 36.013, and 37.011 across the impacted product lines. Rockwell Automation reported the vulnerability to CISA and recommends updating to the patched firmware versions. The advisory affects critical manufacturing infrastructure deployed worldwide. No known public exploitation has been reported at the time of publication.