Executive Summary
In July 2026, multiple vulnerabilities were identified in Rockwell Automation's Studio 5000 Logix Designer software, including CVE-2026-9108, CVE-2026-9127, and CVE-2026-9128. These flaws encompass path traversal issues, incorrect authorization, and unquoted search paths, potentially allowing attackers to execute arbitrary code on affected systems. The vulnerabilities impact versions V32.00 through V36.00 of the software. (rockwellautomation.com)
The discovery of these vulnerabilities underscores the critical need for robust security measures in industrial control systems. Organizations utilizing affected versions should promptly apply the recommended updates to mitigate potential risks associated with these security flaws.
Why This Matters Now
The identification of these vulnerabilities highlights the ongoing challenges in securing industrial control systems, emphasizing the importance of timely software updates and adherence to security best practices to prevent potential exploitation.
Attack Path Analysis
An attacker exploits a path traversal vulnerability in Studio 5000 Logix Designer by crafting a malicious ACD project file, leading to arbitrary file writes and potential code execution. The attacker then modifies external tool configurations to point to malicious executables, escalating privileges. Utilizing the compromised system, the attacker moves laterally within the network to access other critical systems. They establish a command and control channel to maintain persistent access and control over the compromised systems. Sensitive data is exfiltrated from the network to an external server controlled by the attacker. Finally, the attacker disrupts operations by executing malicious code, causing system downtime and data loss.
Kill Chain Progression
Initial Compromise
Description
An attacker exploits a path traversal vulnerability in Studio 5000 Logix Designer by crafting a malicious ACD project file, leading to arbitrary file writes and potential code execution.
Related CVEs
CVE-2026-9108
CVSS 5.4A path traversal vulnerability in Studio 5000 Logix Designer allows attackers to write arbitrary files, potentially leading to code execution.
Affected Products:
Rockwell Automation Studio 5000 Logix Designer – V36.00, V35.00, V35.01, V34.00, V34.01, V34.02, V34.03, V33.00, V33.01, V33.02, V33.03, V32.00, V32.01, V32.02, V32.03, V32.04
Exploit Status:
no public exploitCVE-2026-9127
CVSS 7.3Incorrect authorization in Studio 5000 Logix Designer allows authenticated users to modify external tool paths, leading to arbitrary code execution.
Affected Products:
Rockwell Automation Studio 5000 Logix Designer – V35.00, V34.00, V34.01, V33.00, V33.02, V32.00, V32.01, V32.02, V32.03, V32.04
Exploit Status:
no public exploitCVE-2026-9128
CVSS 7.3An unquoted search path in Studio 5000 Logix Designer's External Tools configuration allows attackers to execute arbitrary code.
Affected Products:
Rockwell Automation Studio 5000 Logix Designer – V35.00, V34.00, V34.01, V34.02, V33.00, V33.01, V33.02, V32.00, V32.01, V32.02, V32.03, V32.04
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Hijack Execution Flow: Path Interception by Unquoted Path
Hijack Execution Flow: Path Interception by PATH Environment Variable
Hijack Execution Flow: Path Interception by Search Order Hijacking
Valid Accounts
Command and Scripting Interpreter
Abuse Elevation Control Mechanism
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that all system components and software are protected from known vulnerabilities by installing applicable security patches
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Asset Management
Control ID: 2.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Industrial Automation
Critical exposure through Rockwell Studio 5000 vulnerabilities enabling arbitrary code execution and configuration tampering in manufacturing control systems.
Automotive
Manufacturing operations face significant risk from path traversal and authorization flaws compromising production line control and safety systems.
Oil/Energy/Solar/Greentech
Energy infrastructure vulnerable to malicious ACD file exploitation and external tool manipulation affecting operational technology and process control.
Food Production
Processing facility control systems susceptible to local privilege escalation and remote code execution through compromised engineering workstations.
Sources
- Rockwell Automation Studio 5000 Logix Designerhttps://www.cisa.gov/news-events/ics-advisories/icsa-26-202-10Verified
- SD1783 | Studio 5000 Logix Designer® – Multiple Vulnerabilitieshttps://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1783.htmlVerified
- CVE-2026-9108 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2026-9108Verified
- CVE-2026-9127 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2026-9127Verified
- CVE-2026-9128 Detailhttps://nvd.nist.gov/vuln/detail/CVE-2026-9128Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally, escalate privileges, and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to execute arbitrary code may be constrained, reducing the likelihood of successful exploitation.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges may be constrained, reducing the likelihood of unauthorized access.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally may be constrained, reducing the likelihood of accessing other critical systems.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels may be constrained, reducing the likelihood of maintaining persistent access.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data may be constrained, reducing the likelihood of data loss.
The attacker's ability to disrupt operations may be constrained, reducing the likelihood of significant system downtime and data loss.
Impact at a Glance
Affected Business Functions
- Industrial Automation System Programming
- Control System Configuration
- Manufacturing Process Management
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of proprietary industrial control system configurations and intellectual property.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within the network.
- • Enforce Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing data exfiltration.
- • Deploy Inline IPS (Suricata) to detect and prevent exploitation of known vulnerabilities.
- • Utilize Threat Detection & Anomaly Response systems to identify and respond to suspicious activities promptly.
- • Regularly update and patch software to mitigate known vulnerabilities.



