CVE-2026-9634: Rockwell Automation Redundancy Module Configuration Tool
High severity, CVSS 7.0. EPSS: 0.1% chance of exploitation in the next 30 days.
A security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non-administrator) users due to incorrect default permissions. If a local attacker places a malicious DLL in such a directory and an administrator subsequently runs the tool, the malicious DLL is loaded into the elevated process and executes with Administrator/SYSTEM privileges.
Affected products
- Rockwell Automation Redundancy Module Configuration Tool: version 10.00.00 only
Published 2026-09-01. Last modified 2026-09-01.