Critical Vulnerabilities in Rockwell Automation Tool Expose Systems to Attacks

Critical Vulnerabilities in Rockwell Automation Tool Expose Systems to Attacks

First seen 2 Sep 2026, 13:13 UTC Cisawww.rockwellautomation.com 60.6

Article Content

Browse articles
ThreatCluster

Rockwell Automation disclosed two critical vulnerabilities (CVE-2026-9633 and CVE-2026-9634) in the Redundancy Module Configuration Tool, affecting versions 9.00.00 through 10.00.00. These vulnerabilities allow local attackers to execute arbitrary code with Administrator/SYSTEM privileges by exploiting incorrect default permissions on writable directories. The issues were identified during internal testing and reported to ensure customer transparency. Rockwell Automation has released version 10.01.00 to address these vulnerabilities. Users unable to upgrade are advised to follow security best practices to mitigate risks. The vulnerabilities impact critical manufacturing sectors globally. CISA has also issued advisories regarding these vulnerabilities.

Key Points: • Two critical vulnerabilities (CVE-2026-9633, CVE-2026-9634) in Rockwell Automation's tool. • Affected versions: Redundancy Module Configuration Tool 9.00.00 to 10.00.00. • Exploitation could allow local attackers to execute code with elevated privileges.

Timeline

2026-09-01
CVE-2026-9633 published
Rockwell Automation disclosed a vulnerability in the Redundancy Module Configuration Tool allowing arbitrary code execution due to incorrect permissions.
Cisa
2026-09-01
CVE-2026-9634 published
Another vulnerability in the same tool was disclosed, enabling local attackers to exploit DLL loading issues.
Cisa
2026-09-01
Vendor fix released
Rockwell Automation released version 10.01.00 to address the identified vulnerabilities.
Cisa
2026-09-02
Advisory portal launched
Rockwell Automation launched a public Security Advisory Portal for easier access to security advisories.
www.rockwellautomation.com