top of page
perceptive_background_267k.jpg

Rockwell Automation FactoryTalk Activation Manager

Published:

1 september 2026 om 14:00:00

Alert date:

1 september 2026 om 19:14:40

Source:

cisa.gov

Click to open the original link from this advisory

Critical Infrastructure, Enterprise Applications, Identity & Access

A privilege escalation vulnerability (CVE-2026-16675) exists in Rockwell Automation FactoryTalk Activation Manager V5.02 and below. The flaw stems from custom installer actions that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated local attacker can hijack these console windows to obtain a SYSTEM-level command prompt, granting full access to files, processes, and system resources. The vulnerability carries a CVSS v3.1 score of 7.8 (HIGH) and CVSS v4.0 score of 8.5 (HIGH). Affected sectors include Critical Manufacturing deployed worldwide. Rockwell Automation recommends updating to V5.03 to remediate the issue. No known public exploitation has been reported to CISA at this time.

Technical details

Mitigation steps:

Affected products:

Rockwell Automation FactoryTalk Activation Manager V5.02 and below

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page