VYPR
advisoryPublished Jul 21, 2026· Updated Jul 22, 2026· 1 source

Rockwell Automation: Six Vulnerabilities Disclosed, Including RCE and Auth Bypass in ICS Products

Key findings • Six vulnerabilities disclosed across Rockwell Automation products on July 21, 2026, including DoS, RCE, and path traversal. • CVE-2026-10714 in FactoryTalk Services Platform al…

Key findings

On July 21, 2026, a batch of six vulnerabilities was disclosed across multiple Rockwell Automation products, with CISA issuing advisories for each. These vulnerabilities span denial-of-service (DoS) conditions, path traversal, and remote code execution, impacting critical industrial control systems and highlighting potential risks to manufacturing operations. The disclosures were coordinated, with CISA releasing advisories for each affected product family on the same day.

Denial-of-Service Vulnerabilities

Two distinct denial-of-service vulnerabilities were detailed. CVE-2026-9140 affects the Rockwell Automation 1718-AENTR/1719-AENTR devices, stemming from improper handling of a UDP unicast network storm that can overload the device, requiring a power cycle for recovery. This impacts versions of the 1718/1719 Ex I/O up to 3.011. Separately, CVE-2026-10573 affects the 1734 POINT I/O module. This DoS vulnerability arises from the improper handling of crafted CIP messages, causing the module to enter a faulted state that necessitates a restart. The affected version for this module is 3.023. Both vulnerabilities carry a CVSSv3 score of 7.5.

Code Execution and Path Traversal

Several vulnerabilities allow for code execution or manipulation of system paths. CVE-2026-9127 and CVE-2026-9128, both affecting Rockwell Automation Studio 5000 Logix Designer, present code execution risks. CVE-2026-9127 arises from incorrect authorization on a configuration file, allowing authenticated users to modify external tool paths, potentially leading to arbitrary code execution. CVE-2026-9128 is due to an unquoted search path in the External Tools configuration, where spaces in paths can be misinterpreted by the operating system, leading to unintended execution. These affect Studio 5000 Logix Designer versions V35.00, V32.00 to V32.04, and V34.00 to V34.03 for CVE-2026-9127, and V35.00 and V32.00 to V32.04 for CVE-2026-9128.

CVE-2026-9108, also impacting Studio 5000 Logix Designer across multiple versions (V36.00, V35.00, V35.01, V34.00-V34.03, V33.00-V33.03, V32.00-V32.04), is a path traversal vulnerability. It occurs due to improper sanitization of file names within ACD project files, allowing path traversal sequences to escape intended directories during project opening.

Authentication Bypass

A critical vulnerability, CVE-2026-10714, affects the Rockwell Automation FactoryTalk Services Platform (FTSP). This issue allows an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability arises because the application does not verify that the JWT algorithm is configured for RSA, enabling an attacker to set the algorithm to "none" and forge authentication tokens. This has a CVSSv3 score of 7.8 and affects FactoryTalk Directory (FTSP) version 6.60.

Response and Mitigation

Rockwell Automation has released patches and advisories for these vulnerabilities. Users are strongly advised to consult the specific CISA ICS advisories (ICSA-26-202-07 through ICSA-26-202-10) for detailed version information and mitigation steps. Applying the latest security updates and patches provided by Rockwell Automation is crucial to protect against these threats.

The coordinated disclosure of these vulnerabilities underscores the ongoing security challenges within the industrial control systems sector. Users of Rockwell Automation products should prioritize updating their systems to mitigate risks associated with DoS, code execution, path traversal, and authentication bypass. Continuous monitoring and adherence to vendor security recommendations are essential for maintaining operational integrity.

Synthesized by Vypr AI