Rockwell Automation FactoryTalk Services Platform
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to impersonate an authorized user on the FTSP server, resulting in unauthorized access to system configurations. The following versions of Rockwell Automation FactoryTalk Services Platform are affected: FactoryTalk Directory (FTSP) 6.60 CVSS Vendor Equipment Vulnerabilities v3 7.8 Rockwell Automation Rockwell Automation FactoryTalk Services Platform Weak Authentication Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-10714 A security issue exists within FactoryTalk Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability stems from the application not verifying that the JWT algorithm is configured for RSA, enabling an attacker to set the algorithm to "none" and craft forged tokens. This could allow an authenticated low-privilege user to impersonate any authorized user on the FTSP server, resulting in unauthorized access to system configuration and the ability to grant permissions to other systems protected by FTSP. View CVE Details Affected Products Rockwell Automation FactoryTalk Services Platform Vendor: Rockwell Automation Product Version: Rockwell Automation FactoryTalk Directory (FTSP): 6.60 Product Status: known_affected Remediations Mitigation Users using FactoryTalk Services Platform v6.60 should apply either the individual patch (RAID 1158263) or the February 2026 Patch Roll-up, or later update. Mitigation Users using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell's security best practices. https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight Mitigation For more information, refer to Rockwell Automation's security advisory SD1786 page. https://www.rockwellautoma
CSIRTS triage
- What
- A vulnerability allows attackers to bypass JWT signature validation.
- Who is affected
- Deployments of FactoryTalk Services Platform version 6.60.
- Urgency
- Critical remediation is necessary due to the potential for unauthorized access.
- Action
- Update to the latest version of FactoryTalk Services Platform.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch FactoryTalk Services Platform
Get an email when a new FactoryTalk Services Platform advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-07
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-107140.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-10714 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Rockwell Automation FactoryTalk
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalRockwell Automation FactoryTalk DataMosaixcisa · 2026-07-16
- medium[NEW] [medium] Rockwell Automation FactoryTalk Services Platform and DataMosaix Private Cloud: Multiple vulner…cert-bund · 2026-07-15
More from CISA Cybersecurity Advisories
- criticalWatchfire Controller Software2026-07-30
- criticalMZ Automation GmbH libiec618502026-07-30
- criticalToptech Systems RCU II+ and Multiload II+2026-07-30
- criticalNASA Core Flight System (cFS) Health & Safety (HS) Application2026-07-30
- criticalMikroTik RouterOS2026-07-30