[NEW] [high] Rockwell Automation FactoryTalk Activation Manager and Historian Machine Edition: Multiple vulnerabilities
An attacker from an adjacent network can exploit multiple vulnerabilities in Rockwell Automation FactoryTalk to execute arbitrary code, obtain administrator privileges, or cause a denial-of-service condition.
CSIRTS triage
- What
- Multiple vulnerabilities allow remote code execution, privilege escalation, and denial-of-service from adjacent networks.
- Who is affected
- Deployments of FactoryTalk on adjacent networks are directly exposed.
- Urgency
- High severity and critical for industrial control; immediate patching is required to prevent code execution and privilege escalation.
- Action
- Apply Rockwell Automation security updates for FactoryTalk immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch FactoryTalk Activation Manager and Historian Machine Edition
Get an email when a new FactoryTalk Activation Manager and Historian Machine Edition advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3143
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-12768 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-12661 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16675 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownCVE-2026-16675: A privilege escalation security issue exists within FactoryTalk® Activation Manager. The secur…nvd
- unknownCVE-2026-12661: A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition. A net…nvd
- unknownCVE-2025-12768: A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-le…nvd
- criticalRockwell Automation Historian MEcisa
- criticalRockwell Automation FactoryTalk Activation Managercisa
Recent advisories for Rockwell Automation FactoryTalk
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalRockwell Automation FactoryTalk Activation Managercisa · 2026-09-01
- criticalRockwell Automation FactoryTalk Services Platformcisa · 2026-07-21
- criticalRockwell Automation FactoryTalk DataMosaixcisa · 2026-07-16
- medium[NEW] [medium] Rockwell Automation FactoryTalk Services Platform and DataMosaix Private Cloud: Multiple vulner…cert-bund · 2026-07-15
More from CERT-Bund (BSI) Security Advisories
- critical[NEW] [high] JFrog Artifactory: Vulnerability allows obtaining administrator privileges2026-09-03
- high[NEW] [high] Golang Go: Multiple vulnerabilities2026-09-02
- high[UPDATE] [high] Golang Go: Multiple vulnerabilities2026-09-02
- medium[NEW] [medium] Node.js: Multiple vulnerabilities2026-09-02
- critical[NEW] [critical] SonicWall SMA: Multiple vulnerabilities2026-09-02