

Affected Environment
Rockwell Automation Studio 5000 Logix Designer, 1734 POINT I/O, 1718/1719-AENTR; Siemens CADRA, IAM Client, SIDIS SmartPlug, Opcenter X, RUGGEDCOM APE1808; Tycon Systems TPDIN-Monitor-WEB2.
Threat Overview
Multiple CVEs covering path traversal, remote code execution, denial of service, authentication bypass, and privilege escalation across OT products from two major vendors.
Exposure Timeline
Advisories issued 22nd July 2026. Rockwell Automation patch versions available; Siemens updates available per individual advisory guidance.
Attack Surface
Industrial programming environments, EtherNet/IP adapters, Siemens IAM and OPC server components, and web-enabled monitoring devices in OT networks.
Technical Root Cause
Studio 5000 flaws include path traversal in ACD project files, incorrect authorisation on configuration files, and unquoted search paths enabling executable hijacking.
Exploitation Pathway
Local or authenticated attacker opens malicious ACD project file or modifies external tool configuration. Network attacker sends crafted CIP messages to trigger DoS on POINT I/O modules.
Operational Impact
Arbitrary code execution and denial of service conditions on industrial programming and control infrastructure. POINT I/O DoS requires device restart to recover.
Strategic Impact
Compromise of Rockwell Studio 5000 or Siemens components in OT environments can directly affect production systems and safety-critical operations.
Required Mitigation
Upgrade Studio 5000 Logix Designer to fixed versions per Rockwell advisory. Migrate 1734 POINT I/O to 5034-OB8. Apply Siemens patches per individual product advisories.
Incident Response Guidance
Review external tool configuration files in Studio 5000 installations for unauthorised modifications. Inspect ACD project files from untrusted sources. Audit CIP traffic for anomalous message patterns.
References
Rockwell Automation Security Advisories, Siemens ProductCERT Advisories, CISA ICS Advisories, CVE-2026-9108, CVE-2026-9127, CVE-2026-9128, CVE-2026-10573
Trusted by clients worldwide






Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.




