CVE-2026-9634
View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to escalate and execute processes with administrator privileges. The following versions of Rockwell Automation Redundancy Module Configuration Tool are affected: Redundancy Module Configuration Tool 10.00.00 (CVE-2026-9633) Redundancy Module Configuration Tool >=9.00.00|<=10.00.00 (CVE-2026-9634) CVSS Vendor Equipment Vulnerabilities v3 7.3 Rockwell Automation Rockwell Automation Redundancy Module Configuration Tool Incorrect Default Permissions Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-9633 A security issue exists within the Redundancy Module Configuration Tool. The RM3ConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non administrator) users due to incorrect default permissions. If a local attacker places a malicious DLL in such a directory and an administrator subsequently runs the tool, the malicious DLL is loaded into the elevated process and executes with Administrator/SYSTEM privileges. View CVE Details Affected Products Rockwell Automation Redundancy Module Configuration Tool Vendor: Rockwell Automation Product Version: Rockwell Automation Redundancy Module Configuration Tool: 10.00.00 Product Status: known_affected Remediations Vendor fix Rockwell Automation has released Redundancy Module Configuration Tool version 10.01.00 for users to install. Mitigation Customers using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices (https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight). https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight Mitigation For more
CSIRTS triage
- What
- Incorrect default permissions and DLL search path vulnerabilities in RM3ConfigTool.exe allow escalation to administrator privileges.
- Who is affected
- Systems with Rockwell Automation Redundancy Module Configuration Tool versions 9.00.00 through 10.00.00 are affected worldwide.
- Urgency
- Critical urgency due to privilege escalation to administrator and CVSS 7.3 score affecting critical manufacturing infrastructure.
- Action
- Update Redundancy Module Configuration Tool to a patched version addressing CVE-2026-9633 and CVE-2026-9634.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-9634
Get an email if CVE-2026-9634 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Advisory coverage (2)
- unknownCVE-2026-9634: A security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe b…nvd · 2026-09-01
- criticalRockwell Automation Redundancy Module Configuration Toolcisa · 2026-09-01
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-9634)