# Rockwell Studio 5000 Logix Designer flaws patched

Published: 2026-07-21 · Severity: medium · Sectors: manufacturing
Canonical: https://vorant.io/reports/81280f38-6f59-5ed7-82df-de10dad37c87/rockwell-studio-5000-logix-designer-flaws-patched

> Rockwell Automation patched three local vulnerabilities in Studio 5000 Logix Designer that could let an attacker execute arbitrary code via malicious project files or configuration tampering.

CISA issued an advisory detailing three vulnerabilities affecting Rockwell Automation's Studio 5000 Logix Designer, a widely used engineering tool for programming Rockwell PLCs in critical manufacturing environments worldwide. The flaws span multiple version ranges from V32.00 through V36.00 and include a path traversal issue in ACD project file handling (CVE-2026-9108), an incorrect authorization flaw allowing authenticated users to redirect external tool paths to malicious executables (CVE-2026-9127), and an unquoted search path vulnerability that could allow execution of attacker-planted binaries (CVE-2026-9128).

All three vulnerabilities require local access or user interaction and have high attack complexity, and CISA states no known public exploitation has been reported. Rockwell has released fixed versions (V32.05, V33.03/04, V34.02/03/04, V35.01/02, V36.01, and V37.00) addressing the respective CVEs, and recommends organizations unable to upgrade immediately follow vendor-published security best practices. The advisory is standard vendor-disclosed patching guidance for the critical manufacturing sector with no evidence of active exploitation or threat actor involvement.

## Mentioned in this report

- Vulnerabilities: CVE-2026-9108, CVE-2026-9127, CVE-2026-9128

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-10

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/81280f38-6f59-5ed7-82df-de10dad37c87/rockwell-studio-5000-logix-designer-flaws-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
