CVE-2026-9127: Rockwellautomation Studio 5000 Logix Designer

High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.

A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a malicious executable, resulting in arbitrary code execution when any user interacts with the external tools functionality.

Affected products

  • Rockwellautomation Studio 5000 Logix Designer: up to and including 32.04; from 33.00, before 33.02 (fixed in 33.02); from 34.00, before 34.02 (fixed in 34.02); version 35.00 only

Published 2026-07-14. Last modified 2026-08-25.