CISA

Rockwell Automation FactoryTalk Activation Manager

From Cybersecurity and Infrastructure Security Agency ↗

The following versions of Rockwell Automation FactoryTalk Activation Manager are affected:

FactoryTalk Activation Manager V5.02_and_below (CVE-2026-16675)

Vendor

Equipment

Rockwell Automation

Rockwell Automation FactoryTalk Activation Manager

Improper Restriction of Excessive Authentication Attempts

Critical Infrastructure Sectors: Critical Manufacturing

Countries/Areas Deployed: Worldwide

Company Headquarters Location: United States

A privilege escalation vulnerability exists within FactoryTalk Activation Manager. The vulnerability stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials could hijack these console windows to obtain a SYSTEM-level command prompt, allowing full access to all files, processes, and system resources.

R...