Rockwell Studio 5000 Logix Designer flaws patched
Rockwell Automation patched three local vulnerabilities in Studio 5000 Logix Designer that could let an attacker execute arbitrary code via malicious project files or configuration tampering.
CISA issued an advisory detailing three vulnerabilities affecting Rockwell Automation's Studio 5000 Logix Designer, a widely used engineering tool for programming Rockwell PLCs in critical manufacturing environments worldwide. The flaws span multiple version ranges from V32.00 through V36.00 and include a path traversal issue in ACD project file handling (CVE-2026-9108), an incorrect authorization flaw allowing authenticated users to redirect external tool paths to malicious executables (CVE-2026-9127), and an unquoted search path vulnerability that could allow execution of attacker-planted binaries (CVE-2026-9128).
All three vulnerabilities require local access or user interaction and have high attack complexity, and CISA states no known public exploitation has been reported. Rockwell has released fixed versions (V32.05, V33.03/04, V34.02/03/04, V35.01/02, V36.01, and V37.00) addressing the respective CVEs, and recommends organizations unable to upgrade immediately follow vendor-published security best practices. The advisory is standard vendor-disclosed patching guidance for the critical manufacturing sector with no evidence of active exploitation or threat actor involvement.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-10
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free