PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-9128 Rockwell Automation CVE debrief

A code execution security issue exists within Studio 5000 Logix Designer due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to unintended executables placed earlier in the search order. This vulnerability could allow an attacker to plant a malicious executable in a location within the search path, resulting in arbitrary code execution with the same permissions of the user running the application. To verify and mitigate this vulnerability, defenders should review the external tools configuration, check for any suspicious or unauthorized executables in the search path, and ensure that all executable paths are properly quoted. Additionally, defenders should monitor system logs for any unusual activity and implement security best practices for Industrial Control Systems. The CVE record was published on 2026-07-21T06:00:00.000Z and has not been modified since then. To address this issue, administrators should prioritize patching Rockwell Automation Studio 5000 Logix Designer and implement security best practices for affected software versions.

Vendor
Rockwell Automation
Product
Studio 5000 Logix Designer
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-21
Advisory published
2026-07-21
Advisory updated
2026-07-21

Who should care

Administrators and users of Rockwell Automation Studio 5000 Logix Designer, especially those in industrial control systems environments, should be aware of this vulnerability and take steps to mitigate it. This includes reviewing and following CISA's recommended practices for Industrial Control Systems, implementing Rockwell Automation's security best practices for affected software versions, and ensuring that all executable paths in the external tools configuration are properly quoted. Additionally, operators and security teams should review the affected product scope and vulnerability class to determine the potential operational impact and implement compensating controls for exposed systems while remediation is scheduled and verified.

Technical summary

A code execution security issue exists within Studio 5000 Logix Designer due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to unintended executables placed earlier in the search order. This vulnerability could allow an attacker to plant a malicious executable in a location within the search path, resulting in arbitrary code execution with the same permissions of the user running the application. To mitigate this vulnerability, administrators should prioritize patching Rockwell Automation Studio 5000 Logix Designer and implement security best practices for affected software versions.

Defensive priority

Administrators should prioritize patching Rockwell Automation Studio 5000 Logix Designer due to the high CVSS score of 7.5 and the potential for arbitrary code execution.

Recommended defensive actions

  • Apply the vendor-provided patches for Studio 5000 Logix Designer: V36.00, 35.01, 34.03, 33.03, 32.05.
  • Implement Rockwell Automation's security best practices for affected software versions.
  • Review and follow CISA's recommended practices for Industrial Control Systems.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Evidence notes

The CVE description notes an unquoted search path issue in Studio 5000 Logix Designer. The external tools configuration file allows paths with spaces that are not properly quoted, potentially leading to code execution if exploited. To verify and mitigate this vulnerability, defenders should review the external tools configuration, check for any suspicious or unauthorized executables in the search path, and ensure that all executable paths are properly quoted. Additionally, defenders should monitor system logs for any unusual activity and implement security best practices for Industrial Control Systems.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T06:00:00.000Z and has not been modified since then.