Thousands of Rockwell Automation programmable logic controllers remain directly reachable from the public internet, including 22 in US cities that have recently reported cyberattacks on water utilities, underscoring the fragile state of industrial control system security.[1][2][3]
Researchers at Forescout’s Vedere Labs used Shodan to scan for devices exposing EtherNet/IP on port 44818 and, on August 3, identified 4,407 internet-facing Rockwell controllers worldwide, with 2,844 located in the United States.[2][3][4] The firm’s analysis shows that 22 exposed controllers sit in municipalities tied to the recent wave of water-utility incidents, and 19 of those ride on the same mobile carrier network, suggesting a common deployment model using cellular gateways for remote access.[1][3][5] Forescout emphasized that the count reflects exposed controllers, not confirmed victims, and said it has no evidence that any of the identified devices have been compromised.[1][2][4]
The risk is amplified by known vulnerabilities affecting Rockwell gear that line up with the way these exposed devices are deployed.[2][9][13] Forescout reported that 19 of the 22 controllers in affected cities run firmware susceptible to CVE-2017-16740, a Modbus TCP buffer overflow in Rockwell MicroLogix devices that carries a vendor-assigned CVSS v3 score of 8.6, allowing a remote attacker to crash or potentially manipulate the controller under certain configurations.[1][5] The company also points out that only one Rockwell Automation / Allen-Bradley controller flaw is currently documented as exploited in real-world attacks: CVE-2021-22681, an authentication-bypass issue in Logix controllers that lets an unauthenticated attacker impersonate a trusted engineering workstation and issue commands to targeted PLCs.[2][10][13] Federal alerts have tied Iranian-affiliated actors to campaigns abusing that same Logix weakness across water, wastewater and energy infrastructure.[9][14]
The exposure figures land amid a broader escalation of attacks on US water systems. An FBI public service announcement in late July describes incidents at water and wastewater utilities in at least seven states that, in some cases, degraded operations.[7] Separate research into the coordinated attacks on Minnesota utilities notes that small and mid-sized systems with internet-facing Rockwell, Schneider Electric or Siemens PLCs were disproportionately affected, often via poorly secured cellular modem links to field equipment.[10][13] Censys telemetry cited in that research found more than 5,200 internet-exposed hosts globally identifying as Rockwell Automation or Allen-Bradley devices, with roughly three-quarters located in the United States and a “disproportionate share” reachable through carrier networks—patterns mirrored in Forescout’s August snapshot.[13] While officials have not publicly attributed the Minnesota incidents, CISA’s July advisory AA26-097A warns that Iranian-affiliated actors are actively scanning and hitting PLCs on ports 44818, 2222, 102 and 502, as well as associated modems.[14]
Even where no exploit has been confirmed, the technical reality of exposing EtherNet/IP services without authentication is stark. Forescout notes that leaving port 44818 open to the internet provides an unauthenticated pathway that can allow an attacker to identify Rockwell controllers and, depending on device configuration, read or write settings remotely.[1][2][5] Many of the exposed devices are older MicroLogix 1400 and 1100 models flagged in recent warnings, which often lack modern security features and are frequently deployed in small municipal and industrial environments with limited OT security staffing.[5][12] The combination of high-severity vulnerabilities like CVE-2017-16740 and remotely exploitable design flaws such as CVE-2021-22681 in environments where PLCs are directly reachable dramatically lowers the barrier for disruptive attacks on water treatment, pumping and distribution processes.[9][10][13]
Forescout and government agencies are urging operators to treat these findings as an operational emergency rather than an abstract exposure metric.[2][10][14] Recommended steps include disconnecting PLCs from direct internet access, or placing them behind secure gateways with strong authentication and logging; disabling or tightly restricting remote cellular modem access except during scheduled maintenance windows; and enforcing IT/OT network segmentation so that engineering workstations cannot be reached from untrusted networks.[10][13][14] Utilities are also advised to inventory all Rockwell controllers against current advisories, apply firmware updates where available, and work with vendor product security incident response teams and sector-specific information sharing bodies to monitor evolving exploitation activity.[7][10][12] With active threat campaigns already targeting similar devices, the cluster of internet-exposed Rockwell PLCs in water-attack cities marks a clear and present danger rather than a hypothetical one.[1][3][14]
References
- Over 4400 Rockwell PLCs Exposed Online, 22 Found in …
- OT Security Analysis: Exposed Devices Attacked in US …
- Thousands of Rockwell Controllers Sit Exposed Online, With 22 in US Water Attack Cities
- Thousands of Rockwell PLCs Are Still Publicly Reachable · PlainSec briefing, 2026-08-07
- Snowflake Plea, 4,407 Exposed PLCs & Three Cisco 9.8s (08/06/2026)
- FBI Public Service Announcement I-073026-PSA
- Iran-linked hackers target water, energy in US, FBI and CISA warn
- CSAI Foundation | Cloud Security Alliance
- US authorities see ‘significant escalation’ in attacks on …
- Minnesota & other US Water Cyber Attacks, CISA AA26-097A
- Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
