CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-16675

criticalcovered by 3 sourcesfirst seen 2026-09-01
View CSAF Summary The following versions of Rockwell Automation FactoryTalk Activation Manager are affected: FactoryTalk Activation Manager V5.02_and_below (CVE-2026-16675) CVSS Vendor Equipment Vulnerabilities v3 7.8 Rockwell Automation Rockwell Automation FactoryTalk Activation Manager Improper Restriction of Excessive Authentication Attempts Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-16675 A privilege escalation vulnerability exists within FactoryTalk Activation Manager. The vulnerability stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials could hijack these console windows to obtain a SYSTEM-level command prompt, allowing full access to all files, processes, and system resources. View CVE Details Affected Products Rockwell Automation FactoryTalk Activation Manager Vendor: Rockwell Automation Product Version: Rockwell Automation FactoryTalk Activation Manager V5.02_and_below Product Status: known_affected Remediations Vendor fix Rockwell Automation recommends users update to software version V5.03. Mitigation Customers using the affected software who are not able to upgrade to one of the corrected versions should use Rockwell Automation's security best practices. Relevant CWE: CWE-307 Improper Restriction of Excessive Authentication Attempts Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 4.0 8.5 HIGH CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Acknowledgments An anonymous security researcher reported this vulnerability to Rockwell Automation, who reported it to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) an

CSIRTS triage

What
Installer custom actions spawn visible console windows with SYSTEM privileges, allowing authenticated attackers to hijack them and escalate privileges.
Who is affected
Windows-based critical manufacturing deployments worldwide using FactoryTalk Activation Manager V5.02 and earlier.
Urgency
Critical severity with CVSS 7.8; privilege escalation to SYSTEM level is achievable during installation or repair operations.
Action
Upgrade to FactoryTalk Activation Manager version above V5.02; restrict user access during installation and repair operations.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-16675

Get an email if CVE-2026-16675 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (3)

External references

NVD record for CVE-2026-16675

CVE.org record

Embed the live status

CVE-2026-16675 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-16675 status](https://www.csirts.com/badge/CVE-2026-16675)](https://www.csirts.com/cve/CVE-2026-16675)