ZeroHour
Product

FactoryTalk Activation Manager

0 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Rockwell Automation FactoryTalk Activation Manager

CISA details CVE-2026-16675, a CVSS 7.8 privilege escalation flaw in Rockwell FactoryTalk Activation Manager V5.02 and below, with vendor fixes available.

CISA issued an ICS advisory for Rockwell Automation FactoryTalk Activation Manager. CVE-2026-16675 is a privilege escalation vulnerability stemming from installer custom actions, scored 7.8. Versions V5.02 and below are affected, and Rockwell Automation has released fixes.

CISA Advisories · 14d agoAdvisoryCVE-2026-16675

Related CVEs

  • Local privilege escalation to SYSTEM in Rockwell Automation FactoryTalk Activation Manager
    CVE-2026-16675 is a local privilege escalation flaw in Rockwell Automation FactoryTalk Activation Manager caused by custom installer actions that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker holding ordinary Windows credentials on the host can hijack one of these console windows to obtain a SYSTEM-level command prompt, gaining full access to all files, processes, and system resources. Exposure is limited to Windows machines where the Activation Manager installer is run or repaired while an untrusted credentialed user is logged on locally. There is no evidence of exploitation so far: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates only about a 0.1% probability of exploitation in the next 30 days (1st percentile). The issue was assigned by Rockwell Automation's PSIRT and carries a CVSS 4.0 score of 8.5 (High) with local attack vector and low privileges required.
    · Rockwell Automation FactoryTalk Activation Managerlarge

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.