Rockwell Automation Studio 5000 Logix Designer
View CSAF Summary Successful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter configurations, or execute arbitrary code. The following versions of Rockwell Automation Studio 5000 Logix Designer are affected: Studio 5000 Logix Designer V36.00 (CVE-2026-9108) Studio 5000 Logix Designer V35.00 (CVE-2026-9108, CVE-2026-9127, CVE-2026-9128) Studio 5000 Logix Designer V35.01 (CVE-2026-9108) Studio 5000 Logix Designer >=V34.00|<=V34.03 (CVE-2026-9108) Studio 5000 Logix Designer >=V33.00|<=V33.03 (CVE-2026-9108) Studio 5000 Logix Designer >=V32.00|<=V32.04 (CVE-2026-9108, CVE-2026-9127, CVE-2026-9128) Studio 5000 Logix Designer V34.00 (CVE-2026-9127) Studio 5000 Logix Designer V34.01 (CVE-2026-9127) Studio 5000 Logix Designer V33.00 (CVE-2026-9127) Studio 5000 Logix Designer V33.02 (CVE-2026-9127) Studio 5000 Logix Designer >=V34.00|<=V34.02 (CVE-2026-9128) Studio 5000 Logix Designer >=V33.00|<=V33.02 (CVE-2026-9128) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation Studio 5000 Logix Designer Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Incorrect Authorization, Unquoted Search Path or Element Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-9108 A path traversal security issue exists within Studio 5000 Logix Designer due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the intended extraction directory. If exploited, an attacker could craft a malicious ACD project file that results in arbitrary files being written to attacker-controlled locations on the file system, potentially leading to code execution. View CVE Details Affected Prod
CSIRTS triage
- What
- Multiple vulnerabilities could allow local attackers to execute arbitrary code.
- Who is affected
- Deployments of Studio 5000 Logix Designer across specified versions.
- Urgency
- Remediation is urgent due to the critical nature of the vulnerabilities.
- Action
- Update to the latest version of Studio 5000 Logix Designer.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Studio 5000 Logix Designer
Get an email when a new Studio 5000 Logix Designer advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-10
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-91080.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all scored CVEs.
- Low exploitation riskCVE-2026-91270.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all scored CVEs.
- Low exploitation riskCVE-2026-91280.10% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-9108 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9127 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-9128 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] Rockwell Automation Studio 5000 Logix Designer: Multiple vulnerabilities allow code executioncert-bund
- unknownCVE-2026-9128: A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted se…nvd
- unknownCVE-2026-9127: A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorre…nvd
- unknownCVE-2026-9108: A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limit…nvd
Recent advisories for Rockwell Automation Studio
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[NEW] [medium] Rockwell Automation Studio 5000 Logix Designer: Multiple vulnerabilities allow code executioncert-bund · 2026-07-15
More from CISA Cybersecurity Advisories
- criticalWatchfire Controller Software2026-07-30
- criticalMZ Automation GmbH libiec618502026-07-30
- criticalToptech Systems RCU II+ and Multiload II+2026-07-30
- criticalNASA Core Flight System (cFS) Health & Safety (HS) Application2026-07-30
- criticalMikroTik RouterOS2026-07-30