ics-otregulatorNewsThe Broadside1 min read

CISA flags Rockwell Studio 5000 path traversal, code execution flaws

Treat ACD project files like executable content until affected engineering workstations move to the corrected Studio 5000 releases.


TL;DR

The Cybersecurity and Infrastructure Security Agency published ICSA-26-202-10 for three Rockwell Automation Studio 5000 Logix Designer vulnerabilities: CVE-2026-9108 path traversal in ACD project-file handling, CVE-2026-9127 incorrect authorization, and CVE-2026-9128 unquoted search path. Affected versions span V32.00 through V36.00. Defense Industrial Base contractors, managed service providers and state chief information security officers supporting critical manufacturing should patch engineering workstations or apply Rockwell's mitigations.

The Cybersecurity and Infrastructure Security Agency's advisory lands at the engineering workstation layer of industrial control system operations. The three Rockwell Automation Studio 5000 Logix Designer issues can allow a local attacker to execute arbitrary files, alter configurations or run arbitrary code. The path traversal flaw is the cleanest warning: the software can mishandle file names embedded in ACD project files during opening, allowing traversal outside the intended extraction directory.

That makes project-file exchange part of the attack surface for critical manufacturing organizations. Studio 5000 workstations are where integrators, plant engineers, contractors and managed service providers handle design and configuration work. Treating this as a plant-network exposure problem alone misses the mechanism CISA describes: exploitation begins when a user opens or interacts with a local file or External Tools functionality.

The affected matrix is finite but easy to misread. CVE-2026-9108 reaches V36.00, V35.00, V35.01, V34.00 through V34.03, V33.00 through V33.03, and V32.00 through V32.04. Rockwell lists V37.00, 36.01, 35.02, 34.04, 33.04 and 32.05 as corrected releases for that flaw. CVE-2026-9127 and CVE-2026-9128 affect narrower V32 through V35 branches, with corrected releases varying by CVE.

Practitioner work is inventory, patch mapping and file handling. Identify every Studio 5000 Logix Designer install on engineering workstations, match its branch to the Rockwell fix, restrict who can open ACD project files, and tighten intake for files from contractors or vendors. For customers that cannot upgrade immediately, CISA points to Rockwell's security best practices. That buys time only if the shop has a patch plan someone owns.


Published ·Deep Fathom