CISA advisory flags vulnerabilities in Rockwell Automation Studio 5000 Logix Designer V35 and V36. A local attacker could execute arbitrary code, alter configurations, or run arbitrary files. Update if you run this engineering software (OT/enterprise sites); most smaller shops won't have it.Cyber Resilience desk
What this means for you — CISO:Patch Studio 5000 Logix Designer V35/V36 per the advisory — these are local-attacker flaws (arbitrary file execution, config tampering, code execution), so lock down who has console access to engineering workstations in the meantime.
What this means for you — Lean IT orgs:This is specialized industrial control software for programming factory equipment — if you don't run PLCs or industrial machinery, this doesn't apply to you.
What this means for you — MSP:Flag any client running Rockwell Studio 5000 V35 or V36 on engineering workstations, confirm patch status, and check that those machines aren't shared or left logged in — the flaws need local access.
What this means for you — Researcher:CVE-2026-9108 spans both V35 and V36; V35 picks up two more CVEs (9127 and a cut-off third) — worth diffing the CSAF for whether these are shared codebase issues or version-specific regressions.