CVE-2021-22681
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a… EPSS 64% (99th percentile).
CISA federal remediation date Mar 26
Vulnerabilities · 193 days ago
CVE-2021-22681 — a cryptographic-key flaw in Rockwell Studio 5000 Logix Designer and Logix PLCs (CompactLogix, ControlLogix, DriveLogix, FlexLogix. CVEs: CVE-2021-22681.
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a… EPSS 64% (99th percentile).
CISA federal remediation date Mar 26
1 source covering this story
Rockwell Vulnerability Allowing Remote ICS Hacking Exploited in Attacks
The vulnerability was disclosed and mitigated in 2021 but its in-the-wild exploitation has only now come to light.
Part of the PlainSec briefing for 2026-03-24