highOther

AutomationDirect Productivity Suite Multiple Vulnerabilities (Local/Physical Attack Vectors)

First seen Jul 19, 2026 · Updated Jul 19, 2026 · CVSS 7

ICSSCADAPLCengineering-workstationdriver-vulnerabilitykernel-memory-corruptionlocal-privilege-escalationcritical-manufacturingCISA-advisory

AutomationDirect Productivity Suite versions up to v4.6.2.2 contain six vulnerabilities including out-of-bounds write/read flaws and a divide-by-zero condition, primarily triggered via crafted IOCTL requests to a kernel driver or malicious USB devices. Exploitation requires local or physical access and could lead to kernel memory corruption, privilege escalation, information disclosure, or denial-of-service on engineering workstations. No known public exploitation has been reported, and the vulnerabilities are not remotely exploitable.

Technical Analysis

The advisory details six CVEs (CVE-2026-60063, CVE-2026-61389, CVE-2026-60140, CVE-2026-57896, CVE-2026-60073, CVE-2026-61378) affecting AutomationDirect Productivity Suite <=v4.6.2.2, an engineering workstation software used to program PLCs. CVE-2026-60063 and CVE-2026-61389 are out-of-bounds write flaws (CWE-787) in kernel driver IOCTL handling, rated CVSS v3.1 7.0/HIGH, enabling local privilege escalation or system instability. CVE-2026-60140 and CVE-2026-57896 are out-of-bounds read issues (CWE-125) via crafted IOCTL requests leading to information disclosure or crashes (CVSS 6.1/MEDIUM), while CVE-2026-60073 is a physical-access USB-based out-of-bounds read allowing kernel memory disclosure or crash (CVSS 5.9/MEDIUM). CVE-2026-61378 is a divide-by-zero (CWE-369) causing denial-of-service (CVSS 5.5/MEDIUM). All vectors require local or physical access, not remote network exploitation, and target the Windows-based engineering software layer rather than the PLC firmware directly. These are OT engineering-workstation vulnerabilities with no direct AI agent system impact, though organizations running AI-driven ICS monitoring or automation agents on the same workstation network should ensure those hosts are similarly hardened against local privilege escalation to prevent lateral compromise of any co-located agent tooling.

Affected Systems

AutomationDirect Productivity Suite versions <=v4.6.2.2 running on engineering workstations used to configure and program AutomationDirect PLCs in critical manufacturing environments worldwide.

Indicators of Compromise

  • No specific IOCs published; advisory concerns unpatched software vulnerabilities rather than active exploitation artifacts.

Remediation Steps

  1. 1

    Update Productivity Suite

    Upgrade to AutomationDirect Productivity Suite v4.7.0.47 or later via the official AutomationDirect software downloads page.

  2. 2

    Isolate engineering workstations

    Disconnect engineering workstations from external networks (internet or corporate LAN) and use dedicated internal or air-gapped networks for device communication.

  3. 3

    Restrict access

    Limit physical and logical access to engineering workstations to authorized personnel only.

  4. 4

    Application whitelisting

    Configure whitelisting to allow only trusted, pre-approved applications and block unauthorized software execution.

  5. 5

    Endpoint protection

    Deploy antivirus/EDR tools and host-based firewalls to detect and block unauthorized access attempts.

  6. 6

    Logging and monitoring

    Enable and regularly review system logs for suspicious or unauthorized activity.

  7. 7

    Backup and recovery

    Maintain secure, tested backups of PLC configurations to minimize downtime from potential incidents.

  8. 8

    Network segmentation

    Ensure control system networks and devices are isolated behind firewalls and not accessible from the internet; use VPNs for necessary remote access.

CVE / Advisory IDs

CVE-2026-60063CVE-2026-61389CVE-2026-60140CVE-2026-57896CVE-2026-60073CVE-2026-61378

Industries Most Exposed

Critical ManufacturingIndustrial Control SystemsOperational Technology

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.