AllCyberNews

CVE-2026-16675

Rockwell Automation FactoryTalk® Activation Manager - Privilege Escalation

CVSS 8.5 high · Rockwell Automation FactoryTalk® Activation Manager · published 2026-09-01

A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials could hijack these console windows to obtain a SYSTEM-level command prompt, allowing full access to all files, processes, and system resources.

Coverage 1 source

  1. 2026-09-01 CISA Cybersecurity Advisories high Rockwell Automation FactoryTalk Activation Manager

    Rockwell Automation FactoryTalk Activation Manager versions V5.02 and below have a vulnerability allowing excessive authentication attempts.

Also covered