VYPR
advisoryPublished Sep 1, 2026· 1 source

Rockwell Automation FactoryTalk Activation Manager Vulnerable to Privilege Escalation

A critical privilege escalation vulnerability in Rockwell Automation's FactoryTalk Activation Manager allows authenticated attackers to gain SYSTEM-level command prompt access.

CISA has issued an advisory detailing a significant privilege escalation vulnerability, identified as CVE-2026-16675, affecting Rockwell Automation's FactoryTalk Activation Manager software. The vulnerability impacts versions V5.02 and below, posing a risk to industrial control systems within the critical manufacturing sector worldwide.

The core of the issue lies within custom actions embedded in the software's installer. During installation or repair operations, these actions spawn visible console windows that execute with SYSTEM privileges. An authenticated attacker who gains access to a system running the vulnerable software could exploit this by hijacking these console windows.

Successful exploitation would grant the attacker a SYSTEM-level command prompt. This level of access allows for complete control over all files, processes, and system resources on the affected machine. The CVSS v3.1 score for this vulnerability is rated as HIGH at 7.8, with a CVSS v4.0 score of 8.5, underscoring the severity of the potential impact.

Rockwell Automation has released version V5.03 of the FactoryTalk Activation Manager as a fix for this vulnerability. The company strongly recommends that all users update to this latest version to mitigate the risk. For organizations unable to upgrade immediately, Rockwell Automation advises adhering to their established security best practices for industrial control systems.

The vulnerability was reported by an anonymous security researcher, who then disclosed it to Rockwell Automation, leading to the subsequent advisory from CISA. While no public exploitation has been reported to CISA at this time, the potential for widespread impact in critical infrastructure environments necessitates prompt attention.

CISA emphasizes that organizations should implement defensive measures to minimize exploitation risks. This includes limiting network exposure for control system devices, isolating them from business networks via firewalls, and using secure remote access methods like updated VPNs. A thorough impact analysis and risk assessment should precede any defensive measure deployment.

This advisory serves as a reminder of the ongoing security challenges within the operational technology (OT) landscape. Vulnerabilities in software used for managing critical industrial processes can have severe consequences, ranging from operational disruption to potential safety risks. Proactive patching and robust security hygiene are paramount for protecting these environments.

Organizations are encouraged to stay informed about ICS advisories and implement recommended cybersecurity strategies. CISA provides resources on its website, including guidance on defense-in-depth strategies and targeted cyber intrusion detection and mitigation, to help bolster the security of industrial control systems.

Synthesized by Vypr AI