LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-22681: Rockwell Multiple Products Insufficient Protected Credentials Vulnerability

RBRecent Breaches Vulnerability Intelligence·Mar 5, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 26, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-22681 to its Known Exploited Vulnerabilities catalog on Mar 5, 2026, with a federal patch deadline of Mar 26, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Multiple Rockwell products contain an insufficient protected credentials vulnerability. Studio 5000 Logix Designer software may allow a key to be discovered. This key is used to verify Logix…

This vulnerability affects multiple Rockwell Automation products and centers on insufficient protection of credentials. In the Studio 5000 Logix Designer software, a key used to verify communication between the design software and Logix controllers can be discovered. An attacker who obtains the key and has network access to a controller could connect an unauthorized application to it. The issue is relevant for organizations running industrial control systems, where controller access can affect process integrity and safety.

How it works

The weakness is classified as CWE-522, insufficiently protected credentials. The software stores or handles the verification key in a manner that permits discovery by an unauthorized party. Once obtained, the key allows an application to present itself as legitimate design software and establish a connection to a Logix controller.

Am I affected? How to find it in your systems

Confirm whether any Rockwell Automation products, particularly Studio 5000 Logix Designer and associated Logix controllers, are present in the environment. Inventory should cover engineering workstations, HMI servers, and any systems that communicate directly with Logix controllers. Because exact affected versions are not listed here, compare installed software against the vendor advisory.

How to remediate

Apply mitigations or updates according to the vendor instructions referenced in the advisory. Where cloud services are involved, follow applicable BOD 22-01 guidance. If no effective mitigation is available, discontinue use of the affected product.

If you can't patch immediately

Until a fix can be applied, reduce exposure by isolating controller networks from general-purpose systems. Monitor for anomalous connection attempts to Logix controllers and alert on traffic that bypasses expected engineering workstations. Consider disabling remote or unauthenticated design-software connections if the operational process permits.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to unauthorized access and subsequent breaches. Organizations can run a free exposure scan of their email addresses against known breach data to check for prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedRockwell · Multiple Products
WeaknessCWE-522
Added to CISA KEVMar 5, 2026
Federal patch deadlineMar 26, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities