CISA published an ICS advisory detailing four denial-of-service vulnerabilities in Rockwell Automation RSLinx Classic versions 4.50 and earlier. The vulnerabilities (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625) can be exploited via crafted CIP packets, causing the RSLinx Classic service to crash and require a restart. Root causes include integer overflow, integer underflow, insufficient data length validation, and classic buffer overflow. CVSS v3.1 scores range from 7.5 to 8.6 (HIGH), while CVSS v4.0 scores range from 8.7 to 9.2 (HIGH to CRITICAL). The fix is available in RSLinx Classic version 4.60. These vulnerabilities affect critical manufacturing sectors worldwide. No known public exploitation has been reported at the time of publication. Rockwell Automation self-reported the vulnerabilities to CISA.