www.rockwellautomation.com
Critical Vulnerabilities in Rockwell Automation Tool Expose Systems to Attacks
Article Content
Rockwell Automation disclosed two critical vulnerabilities (CVE-2026-9633 and CVE-2026-9634) in the Redundancy Module Configuration Tool, affecting versions 9.00.00 through 10.00.00. These vulnerabilities allow local attackers to execute arbitrary code with Administrator/SYSTEM privileges by exploiting incorrect default permissions on writable directories. The issues were identified during internal testing and reported to ensure customer transparency. Rockwell Automation has released version 10.01.00 to address these vulnerabilities. Users unable to upgrade are advised to follow security best practices to mitigate risks. The vulnerabilities impact critical manufacturing sectors globally. CISA has also issued advisories regarding these vulnerabilities.
Key Points: • Two critical vulnerabilities (CVE-2026-9633, CVE-2026-9634) in Rockwell Automation's tool. • Affected versions: Redundancy Module Configuration Tool 9.00.00 to 10.00.00. • Exploitation could allow local attackers to execute code with elevated privileges.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.