INTEL_REPORT
CISA Cybersecurity Advisories · published 7/16/2026, 12:00:00 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Rockwell Automation Flex 5000 Adapter View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition on the affected product. The following versions of Rockwell Automation Flex 5000 Adapter are affected: Flex 5000 Adapter 6.011 (CVE-2026-12659) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation Flex 5000 Adapter Double Free Background Critical Infrastructure Sectors: Critical Ma…
https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-08
sha256:19e641525d6a017bc78c41723672c5deae0887f126fcb673bba1085879129f86
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| url |
| https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight |
| Open → |
| domain | advisory.sd1789.html | Open → |
| url | https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1789.html | Open → |
| cve | CVE-2026-12659 | Open → |