Multiple High‑Severity Vulnerabilities (CVE‑2026‑60063, CVE‑2026‑61389, CVE‑2026‑60140, CVE‑2026‑57896, CVE‑2026‑60073, CVE‑2026‑61378) in AutomationDirect Productivity Suite
What It Is — CISA issued an advisory that flags six CVEs in AutomationDirect Productivity Suite versions ≤ v4.6.2.2. The flaws are out‑of‑bounds reads/writes and a divide‑by‑zero condition that can be triggered via a crafted IOCTL request.
Exploitability — Exploits require local or physical access; no public exploit code is known, but successful use can corrupt kernel memory, elevate privileges, disclose data, or cause denial‑of‑service. CVSS v3.1 base score 7.0 (High).
Affected Products — AutomationDirect Productivity Suite ≤ v4.6.2.2, a control‑system application deployed worldwide in the critical manufacturing sector.
Why It Matters for Compliance & Audit Readiness
- The vulnerabilities expose a control‑mapping gap that can be cited as a deficiency under SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management).
- Demonstrating timely patching is a core piece of audit evidence; failure to remediate may be viewed as inadequate risk‑mitigation in a SOC 2 audit.
- Local privilege‑escalation flaws undermine the “least‑privilege” principle documented in your access‑control policies, affecting SOC 2 CC6.2 (Logical Access).
Recommended Actions
- Map each CVE to the corresponding SOC 2 control in your compliance inventory.
- Apply AutomationDirect’s update to Productivity Suite v4.7.0.47 or later.
- Capture patch‑deployment artifacts (change‑request tickets, system‑scan logs) for audit trails.
- Verify that physical‑access and workstation‑hardening controls meet SOC 2 CC6.2 requirements.
Source: CISA Advisory – ICSA‑26‑197‑04