Rockwell Automation FactoryTalk Activation Manager
CISA details CVE-2026-16675, a CVSS 7.8 privilege escalation flaw in Rockwell FactoryTalk Activation Manager V5.02 and below, with vendor fixes available.
CISA issued an ICS advisory for Rockwell Automation FactoryTalk Activation Manager. CVE-2026-16675 is a privilege escalation vulnerability stemming from installer custom actions, scored 7.8. Versions V5.02 and below are affected, and Rockwell Automation has released fixes.
- CVE-2026-16675 enables privilege escalation
- FactoryTalk Activation Manager V5.02 and below affected
- CVSS v3 base score of 7.8
- Fix provided by Rockwell Automation
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-16675 | Local privilege escalation to SYSTEM in Rockwell Automation FactoryTalk Activation Manager CVE-2026-16675 is a local privilege escalation flaw in Rockwell Automation FactoryTalk Activation Manager caused by custom installer actions that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker holding ordinary Windows credentials on the host can hijack one of these console windows to obtain a SYSTEM-level command prompt, gaining full access to all files, processes, and system resources. Exposure is limited to Windows machines where the Activation Manager installer is run or repaired while an untrusted credentialed user is logged on locally. There is no evidence of exploitation so far: no public proof-of-concept is known, the flaw is not in CISA KEV, and EPSS estimates only about a 0.1% probability of exploitation in the next 30 days (1st percentile). The issue was assigned by Rockwell Automation's PSIRT and carries a CVSS 4.0 score of 8.5 (High) with local attack vector and low privileges required. Do: Avoid running the FactoryTalk Activation Manager installer or repair operation while untrusted users are logged on to the machine, and restrict local interactive logon rights on hosts where it is installed. Check the Rockwell Automation PSIRT advisory for the affected/fixed version list and upgrade to the fixed release when available. Review which users hold local Windows credentials on engineering workstations and servers hosting Rockwell licensing tools, since the attack requires an authenticated local account. | 8.5 | <1% |
| largeon the order of 100,000+ installations (engineering workstations and servers running Rockwell licensing software) |
View CSAF Summary The following versions of Rockwell Automation FactoryTalk Activation Manager are affected: FactoryTalk Activation Manager V5.02_and_below (CVE-2026-16675) CVSS Vendor Equipment Vulnerabilities v3 7.8 Rockwell Automation Rockwell Automation FactoryTalk Activation Manager Improper Restriction of Excessive Authentication Attempts Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-16675 A privilege escalation vulnerability exists within FactoryTalk Activation Manager. The vulnerability stems from custom actions in the installer that spawn…
This source does not provide full text. Read it at cisa.gov.