CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Rockwell Automation FactoryTalk Activation Manager

criticalCVE-2026-16675
View CSAF Summary The following versions of Rockwell Automation FactoryTalk Activation Manager are affected: FactoryTalk Activation Manager V5.02_and_below (CVE-2026-16675) CVSS Vendor Equipment Vulnerabilities v3 7.8 Rockwell Automation Rockwell Automation FactoryTalk Activation Manager Improper Restriction of Excessive Authentication Attempts Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-16675 A privilege escalation vulnerability exists within FactoryTalk Activation Manager. The vulnerability stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials could hijack these console windows to obtain a SYSTEM-level command prompt, allowing full access to all files, processes, and system resources. View CVE Details Affected Products Rockwell Automation FactoryTalk Activation Manager Vendor: Rockwell Automation Product Version: Rockwell Automation FactoryTalk Activation Manager V5.02_and_below Product Status: known_affected Remediations Vendor fix Rockwell Automation recommends users update to software version V5.03. Mitigation Customers using the affected software who are not able to upgrade to one of the corrected versions should use Rockwell Automation's security best practices. Relevant CWE: CWE-307 Improper Restriction of Excessive Authentication Attempts Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 4.0 8.5 HIGH CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Acknowledgments An anonymous security researcher reported this vulnerability to Rockwell Automation, who reported it to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) an

CSIRTS triage

What
Installer custom actions spawn visible console windows with SYSTEM privileges, allowing authenticated attackers to hijack them and escalate privileges.
Who is affected
Windows-based critical manufacturing deployments worldwide using FactoryTalk Activation Manager V5.02 and earlier.
Urgency
Critical severity with CVSS 7.8; privilege escalation to SYSTEM level is achievable during installation or repair operations.
Action
Upgrade to FactoryTalk Activation Manager version above V5.02; restrict user access during installation and repair operations.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch FactoryTalk Activation Manager

Get an email when a new FactoryTalk Activation Manager advisory drops — max one per day, one-click unsubscribe.

Details

Source
CISA Cybersecurity Advisories (US · national-cert · site)
Severity
critical
Published
2026-09-01
Exploitation
Not in CISA KEV at last sync

Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-04

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-16675coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Rockwell Automation FactoryTalk

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CISA Cybersecurity Advisories