Skip to content
← All articles
Top Cybersecurity News·September 1, 2026·Cybersecurity PSA

Rockwell Automation FactoryTalk Activation Manager

Voice options

Voice names come from your browser and device.

CISA Cybersecurity Advisories & Alerts ↗
TL;DR
The fast version

View CSAF Summary The following versions of Rockwell Automation FactoryTalk Activation Manager are affected: FactoryTalk Activation Manager V5.02_and_below (CVE-2026-16675) CVSS Vendor Equipment Vulnerabilities v3 7.8 Rockwell Automation Rockwell Automation FactoryTalk Activation Manager Improper Restriction of Excessive Authentication Attempts Background Critical Infrastructure Sectors:…

Detailed briefing

What happened

View CSAF Summary The following versions of Rockwell Automation FactoryTalk Activation Manager are affected: FactoryTalk Activation Manager V5.02_and_below (CVE-2026-16675) CVSS Vendor Equipment Vulnerabilities v3 7.8 Rockwell Automation Rockwell Automation FactoryTalk Activation Manager Improper Restriction of Excessive Authentication Attempts…

The vulnerability stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations.

What is verified

An authenticated attacker with Windows credentials could hijack these console windows to obtain a SYSTEM-level command prompt, allowing full access to all files, processes, and system resources.

View CVE Details Affected Products Rockwell Automation FactoryTalk Activation Manager Vendor: Rockwell Automation Product Version: Rockwell Automation FactoryTalk Activation Manager V5.02_and_below Product Status: known_affected Remediations Vendor fix Rockwell Automation recommends users update to software version V5.03.

Mitigation Customers using the affected software who are not able to upgrade to one of the corrected versions should use Rockwell Automation's security best practices.

Why it matters

A security flaw matters when an attacker can use it to cross a trust boundary, gain access, run code, bypass authentication, or expose data. The exact risk depends on the affected product, vulnerable versions, exploit conditions, and whether exploitation has been observed. Those details should come from the cited source rather than assumption.

What you should do

Check the vendor or authoritative advisory for affected versions and remediation. Apply the recommended update or mitigation, restart devices or services when required, and prioritize internet-facing or privileged systems. If the source does not report active exploitation, do not treat exploitation as confirmed.