AutomationDirect Productivity Suite Multiple Vulnerabilities (Local/Physical Attack Vectors)
First seen Jul 19, 2026 · Updated Jul 19, 2026 · CVSS 7
AutomationDirect Productivity Suite versions up to v4.6.2.2 contain six vulnerabilities including out-of-bounds write/read flaws and a divide-by-zero condition, primarily triggered via crafted IOCTL requests to a kernel driver or malicious USB devices. Exploitation requires local or physical access and could lead to kernel memory corruption, privilege escalation, information disclosure, or denial-of-service on engineering workstations. No known public exploitation has been reported, and the vulnerabilities are not remotely exploitable.
Technical Analysis
The advisory details six CVEs (CVE-2026-60063, CVE-2026-61389, CVE-2026-60140, CVE-2026-57896, CVE-2026-60073, CVE-2026-61378) affecting AutomationDirect Productivity Suite <=v4.6.2.2, an engineering workstation software used to program PLCs. CVE-2026-60063 and CVE-2026-61389 are out-of-bounds write flaws (CWE-787) in kernel driver IOCTL handling, rated CVSS v3.1 7.0/HIGH, enabling local privilege escalation or system instability. CVE-2026-60140 and CVE-2026-57896 are out-of-bounds read issues (CWE-125) via crafted IOCTL requests leading to information disclosure or crashes (CVSS 6.1/MEDIUM), while CVE-2026-60073 is a physical-access USB-based out-of-bounds read allowing kernel memory disclosure or crash (CVSS 5.9/MEDIUM). CVE-2026-61378 is a divide-by-zero (CWE-369) causing denial-of-service (CVSS 5.5/MEDIUM). All vectors require local or physical access, not remote network exploitation, and target the Windows-based engineering software layer rather than the PLC firmware directly. These are OT engineering-workstation vulnerabilities with no direct AI agent system impact, though organizations running AI-driven ICS monitoring or automation agents on the same workstation network should ensure those hosts are similarly hardened against local privilege escalation to prevent lateral compromise of any co-located agent tooling.
Affected Systems
AutomationDirect Productivity Suite versions <=v4.6.2.2 running on engineering workstations used to configure and program AutomationDirect PLCs in critical manufacturing environments worldwide.
Indicators of Compromise
- No specific IOCs published; advisory concerns unpatched software vulnerabilities rather than active exploitation artifacts.
Remediation Steps
- 1
Update Productivity Suite
Upgrade to AutomationDirect Productivity Suite v4.7.0.47 or later via the official AutomationDirect software downloads page.
- 2
Isolate engineering workstations
Disconnect engineering workstations from external networks (internet or corporate LAN) and use dedicated internal or air-gapped networks for device communication.
- 3
Restrict access
Limit physical and logical access to engineering workstations to authorized personnel only.
- 4
Application whitelisting
Configure whitelisting to allow only trusted, pre-approved applications and block unauthorized software execution.
- 5
Endpoint protection
Deploy antivirus/EDR tools and host-based firewalls to detect and block unauthorized access attempts.
- 6
Logging and monitoring
Enable and regularly review system logs for suspicious or unauthorized activity.
- 7
Backup and recovery
Maintain secure, tested backups of PLC configurations to minimize downtime from potential incidents.
- 8
Network segmentation
Ensure control system networks and devices are isolated behind firewalls and not accessible from the internet; use VPNs for necessary remote access.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.