


Perceptive Security
SOC/SIEM Consultancy

Rockwell Automation FactoryTalk Activation Manager
Published:
1 september 2026 om 14:00:00
Alert date:
1 september 2026 om 19:14:40
Source:
cisa.gov
Critical Infrastructure, Enterprise Applications, Identity & Access
A privilege escalation vulnerability (CVE-2026-16675) exists in Rockwell Automation FactoryTalk Activation Manager V5.02 and below. The flaw stems from custom installer actions that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated local attacker can hijack these console windows to obtain a SYSTEM-level command prompt, granting full access to files, processes, and system resources. The vulnerability carries a CVSS v3.1 score of 7.8 (HIGH) and CVSS v4.0 score of 8.5 (HIGH). Affected sectors include Critical Manufacturing deployed worldwide. Rockwell Automation recommends updating to V5.03 to remediate the issue. No known public exploitation has been reported to CISA at this time.
Technical details
Mitigation steps:
Affected products:
Rockwell Automation FactoryTalk Activation Manager V5.02 and below
Related links:
https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-04
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-244-04.json
https://www.cve.org/CVERecord?id=CVE-2026-16675
https://cwe.mitre.org/data/definitions/307.html
https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
https://www.cisa.gov/notification
https://www.cisa.gov/privacy-policy
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
