Skip to content
You can now search across every topic, entity and event.What's new
MicroLogix
Product

MicroLogix

Rockwell Automation's MicroLogix programmable logic controller line, including the 1100 and 1400 models.

MicroLogix is Rockwell Automation's programmable-logic-controller line; its 1100 and 1400 models are covered by advisory SD1790, published 30 July 2026 with operational recovery guidance rather than a patch.

Last refreshed: 3 August 2026 · Appears in 1 active topic

Key Question

Which MicroLogix models were covered by Rockwell's July 2026 advisory?

Timeline for MicroLogix

#12 29 Jul

The alert's citations predate the alert

Cybersecurity: Threats and Defences
View full timeline →

Background

MicroLogix is Rockwell Automation's line of programmable logic controllers, small industrial computers used to automate machinery and processes in manufacturing and utility settings. The 1100 and 1400 models are the versions named in advisory SD1790.

That advisory, published 30 July 2026 and revised the next day, carries no attached CVE and offers steps to recover a locked device rather than a fix for a discovered vulnerability. CISA's own alert on the matter cited NCSC's Secure Connectivity Principles for Operational Technology guidance, which predates the advisory by more than two years, a chronology worth noting precisely rather than glossing over.

No exploitation, attacker technique or affected-customer count has yet been reported for this advisory.

Common Questions
What is MicroLogix?
MicroLogix is Rockwell Automation's family of compact programmable logic controllers used to run automated industrial and utility processes, including the 1100 and 1400 models.Source: Rockwell Automation advisory SD1790
Which MicroLogix models are covered by advisory SD1790?
SD1790 covers both the 1100 and 1400 models, though CISA's own alert on the same campaign named only the 1400.Source: Rockwell Automation advisory SD1790
Why were MicroLogix controllers locked out by attackers?
Attackers changed device passwords on internet-exposed MicroLogix controllers at water and wastewater facilities, prompting CISA's 30 July 2026 alert and Rockwell's recovery guidance.Source: Rockwell Automation advisory SD1790
Is SD1790 a patch for a MicroLogix vulnerability?
No. SD1790 is operational recovery guidance for a locked device, not a vulnerability disclosure, and no CVE is attached to it.Source: Rockwell Automation advisory SD1790