CVE-2026-60073
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with local or physical access to cause memory corruption, unintended information disclosure, application instability, or a denial-of-service condition in the affected product. The following versions of AutomationDirect Productivity Suite are affected: Productivity Suite <=v4.6.2.2 (CVE-2026-60063, CVE-2026-61389, CVE-2026-60140, CVE-2026-57896, CVE-2026-60073, CVE-2026-61378) CVSS Vendor Equipment Vulnerabilities v3 7 AutomationDirect AutomationDirect Productivity Suite Out-of-bounds Write, Out-of-bounds Read, Divide By Zero Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-60063 An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption via a crafted IOCTL request, potentially resulting in privilege escalation or system instability. View CVE Details Affected Products AutomationDirect Productivity Suite Vendor: AutomationDirect Product Version: AutomationDirect Productivity Suite: <=v4.6.2.2 Product Status: known_affected Remediations Mitigation AutomationDirect recommends that users update Productivity suite to v4.7.0.47 and above https://www.automationdirect.com/support/software-downloads. https://www.automationdirect.com/support/software-downloads Mitigation If the update cannot be applied right away, the following compensating controls are recommended until the upgrade can be performed. Mitigation Disconnect the engineering workstation from external networks (e.g., the internet or corporate LAN) to reduce exposure. Mitigation Use only trusted, dedicated internal networks or air-gapped systems for device communication. Mitigation Restrict both physical and logical access to authorized personnel only. Mitigation Configure whitelisting so that only trusted, pre-approved applicati
CSIRTS triage
- What
- Exploitation could lead to memory corruption and application instability.
- Who is affected
- Users of AutomationDirect Productivity Suite version 4.6.2.2 or earlier.
- Urgency
- Remediation is critical due to the potential for severe application issues.
- Action
- Users should update to a version later than 4.6.2.2.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-60073
Get an email if CVE-2026-60073 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
Advisory coverage (2)
- mediumCVE-2026-60073: An out-of-bounds read in the Productivity Suite allows a physical attacker to control the leng…nvd · 2026-07-16
- criticalAutomationDirect Productivity Suitecisa · 2026-07-16
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-60073)