Rockwell Automation FactoryTalk Activation Manager
View CSAF Summary The following versions of Rockwell Automation FactoryTalk Activation Manager are affected: FactoryTalk Activation Manager V5.02_and_below (CVE-2026-16675) CVSS Vendor Equipment Vulnerabilities v3 7.8 Rockwell Automation Rockwell Automation FactoryTalk Activation Manager Improper Restriction of Excessive Authentication Attempts Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-16675 A privilege escalation vulnerability exists within FactoryTalk Activation Manager. The vulnerability stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials could hijack these console windows to obtain a SYSTEM-level command prompt, allowing full access to all files, processes, and system resources. View CVE Details Affected Products Rockwell Automation FactoryTalk Activation Manager Vendor: Rockwell Automation Product Version: Rockwell Automation FactoryTalk Activation Manager V5.02_and_below Product Status: known_affected Remediations Vendor fix Rockwell Automation recommends users update to software version V5.03. Mitigation Customers using the affected software who are not able to upgrade to one of the corrected versions should use Rockwell Automation's security best practices. Relevant CWE: CWE-307 Improper Restriction of Excessive Authentication Attempts Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 4.0 8.5 HIGH CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Acknowledgments An anonymous security researcher reported this vulnerability to Rockwell Automation, who reported it to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) an
CSIRTS triage
- What
- Installer custom actions spawn visible console windows with SYSTEM privileges, allowing authenticated attackers to hijack them and escalate privileges.
- Who is affected
- Windows-based critical manufacturing deployments worldwide using FactoryTalk Activation Manager V5.02 and earlier.
- Urgency
- Critical severity with CVSS 7.8; privilege escalation to SYSTEM level is achievable during installation or repair operations.
- Action
- Upgrade to FactoryTalk Activation Manager version above V5.02; restrict user access during installation and repair operations.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch FactoryTalk Activation Manager
Get an email when a new FactoryTalk Activation Manager advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-04
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-166750.10% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-16675 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Rockwell Automation FactoryTalk
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Rockwell Automation FactoryTalk Activation Manager and Historian Machine Edition: Multiple vulner…cert-bund · 2026-09-02
- criticalRockwell Automation FactoryTalk Services Platformcisa · 2026-07-21
- criticalRockwell Automation FactoryTalk DataMosaixcisa · 2026-07-16
- medium[NEW] [medium] Rockwell Automation FactoryTalk Services Platform and DataMosaix Private Cloud: Multiple vulner…cert-bund · 2026-07-15
More from CISA Cybersecurity Advisories
- criticalCommunicating Under Pressure: Best Practices for Service Providers2026-09-02
- highCISA Adds Seven Known Exploited Vulnerabilities to Catalog2026-09-02
- criticalRockwell Automation Redundancy Module Configuration Tool2026-09-01
- criticalRockwell Automation Logix Platform2026-09-01
- criticalRockwell Automation Historian ME2026-09-01