CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Rockwell Automation Studio 5000 Logix Designer

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2936

As cited

Copy frozen at (site build).

vulnerabilities

Rockwell Automation Studio 5000 Logix Designer

Rockwell Automation has disclosed multiple vulnerabilities in Studio 5000 Logix Designer affecting versions 32.00 through 36.00, including path traversal (CVE-2026-9108), incorrect authorization (CVE-2026-9127), and unquoted search path flaws (CVE-2026-9128) with CVSS scores up to 6.7. Local attackers could exploit these issues to write arbitrary files, modify configurations, or execute code by crafting malicious ACD project files or modifying application settings. Rockwell recommends upgrading to patched versions 37.00, 36.01, 35.02, 34.04, 33.04, or 32.05.

Why it matters: Manufacturing and critical infrastructure operators using affected Studio 5000 Logix Designer versions must patch immediately to prevent code execution on engineering workstations that could compromise industrial control system integrity and safety.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Rockwell Automation Studio 5000 Logix Designer

Rockwell Automation has disclosed multiple vulnerabilities in Studio 5000 Logix Designer affecting versions 32.00 through 36.00, including path traversal (CVE-2026-9108), incorrect authorization (CVE-2026-9127), and unquoted search path flaws (CVE-2026-9128) with CVSS scores up to 6.7. Local attackers could exploit these issues to write arbitrary files, modify configurations, or execute code by crafting malicious ACD project files or modifying application settings. Rockwell recommends upgrading to patched versions 37.00, 36.01, 35.02, 34.04, 33.04, or 32.05.

Why it matters: Manufacturing and critical infrastructure operators using affected Studio 5000 Logix Designer versions must patch immediately to prevent code execution on engineering workstations that could compromise industrial control system integrity and safety.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary