PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-9128 Rockwell Automation CVE debrief

A code execution security issue exists within Studio 5000 Logix Designer due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to unintended executables placed earlier in the search order. This vulnerability could allow an attacker to plant a malicious executable in a location within the search path, resulting in arbitrary code execution with the same permissions of the user running the application. To verify and mitigate this vulnerability, defenders should review the external tools configuration, check for any suspicious or unauthorized executables in the search path, and ensure that all executable paths are properly quoted. Additionally, defenders should monitor system logs for any unusual activity and implement security best practices for Industrial Control Systems. The CVE record was published on 2026-07-21T06:00:00.000Z and has not been modified since then. To address this issue, administrators should prioritize patching Rockwell Automation Studio 5000 Logix Designer and implement security best practices for affected software versions.

Vendor
Rockwell Automation
Product
Studio 5000 Logix Designer
CVSS
HIGH 7.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-14
Original CVE updated
2026-08-25
Advisory published
2026-07-14
Advisory updated
2026-08-25

Who should care

Administrators and users of Rockwell Automation Studio 5000 Logix Designer, especially those in industrial control systems environments, should be aware of this vulnerability and take steps to mitigate it. This includes reviewing and following CISA's recommended practices for Industrial Control Systems, implementing Rockwell Automation's security best practices for affected software versions, and ensuring that all executable paths in the external tools configuration are properly quoted. Additionally, operators and security teams should review the affected product scope and vulnerability class to determine the potential operational impact and implement compensating controls for exposed systems while remediation is scheduled and verified.

Technical summary

A code execution security issue exists within Studio 5000 Logix Designer due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to unintended executables placed earlier in the search order. This vulnerability could allow an attacker to plant a malicious executable in a location within the search path, resulting in arbitrary code execution with the same permissions of the user running the application. To mitigate this vulnerability, administrators should prioritize patching Rockwell Automation Studio 5000 Logix Designer and implement security best practices for affected software versions.

Defensive priority

Administrators should prioritize patching Rockwell Automation Studio 5000 Logix Designer due to the high CVSS score of 7.5 and the potential for arbitrary code execution.

Recommended defensive actions

  • Apply the vendor-provided patches for Studio 5000 Logix Designer: V36.00, 35.01, 34.03, 33.03, 32.05.
  • Implement Rockwell Automation's security best practices for affected software versions.
  • Review and follow CISA's recommended practices for Industrial Control Systems.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Evidence notes

The CVE description notes an unquoted search path issue in Studio 5000 Logix Designer. The external tools configuration file allows paths with spaces that are not properly quoted, potentially leading to code execution if exploited. To verify and mitigate this vulnerability, defenders should review the external tools configuration, check for any suspicious or unauthorized executables in the search path, and ensure that all executable paths are properly quoted. Additionally, defenders should monitor system logs for any unusual activity and implement security best practices for Industrial Control Systems.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-9128 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-9128

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-9128 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9128

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-202-10.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-10

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.