IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Rockwell Automation FactoryTalk Activation Manager

HIGH
CVSS 7.8
Date 2026-09-01T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-16675 7.8 high
A privilege escalation vulnerability exists within FactoryTalk Activation Manager. The vulnerability stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials could hijack these console windows to obtain a SYSTEM-level command prompt, allowing full access to all files, processes, and system resources.

// Remediations (2)

Mitigation: Customers using the affected software who are not able to upgrade to one of the corrected versions s
Customers using the affected software who are not able to upgrade to one of the corrected versions should use Rockwell Automation's security best practices.
Patch: Rockwell Automation recommends users update to software version V5.03.
Rockwell Automation recommends users update to software version V5.03.

// References