CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Rockwell Automation FactoryTalk Services Platform

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2938

As cited

Copy frozen at (site build).

vulnerabilities

Rockwell Automation FactoryTalk Services Platform

Rockwell Automation disclosed a critical vulnerability (CVE-2026-10714) in FactoryTalk Services Platform v6.60 that allows attackers to bypass JWT signature validation and forge authentication tokens. An authenticated low-privilege user could exploit this flaw to impersonate any authorized user, gaining unauthorized access to system configurations and permissions. Rockwell released patches, including a February 2026 roll-up and individual RAID 1158263, to remediate the issue.

Why it matters: Manufacturing organizations running FTSP 6.60 need to patch immediately; unauthorized access to factory automation configurations and cross-system permission escalation pose direct operational and safety risks to industrial control systems.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Rockwell Automation FactoryTalk Services Platform

Rockwell Automation disclosed a critical vulnerability (CVE-2026-10714) in FactoryTalk Services Platform v6.60 that allows attackers to bypass JWT signature validation and forge authentication tokens. An authenticated low-privilege user could exploit this flaw to impersonate any authorized user, gaining unauthorized access to system configurations and permissions. Rockwell released patches, including a February 2026 roll-up and individual RAID 1158263, to remediate the issue.

Why it matters: Manufacturing organizations running FTSP 6.60 need to patch immediately; unauthorized access to factory automation configurations and cross-system permission escalation pose direct operational and safety risks to industrial control systems.

VendorsOkta
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary