CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Rockwell Automation FactoryTalk Activation Manager

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5492

As cited

Copy frozen at (site build).

vulnerabilities

Rockwell Automation FactoryTalk Activation Manager

Rockwell Automation released a security advisory for CVE-2026-16675 affecting FactoryTalk Activation Manager V5.02 and below, a privilege escalation vulnerability with a CVSS score of 7.8. An authenticated attacker with Windows credentials could hijack console windows spawned during installation or repair to obtain SYSTEM-level command access. The vendor recommends updating to version V5.03.

Why it matters: Manufacturing organizations worldwide using FactoryTalk Activation Manager V5.02 or earlier face privilege escalation risk during system installation or repair; immediate patching to V5.03 is required to prevent local attackers from gaining full system control on critical infrastructure assets.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Rockwell Automation FactoryTalk Activation Manager

Rockwell Automation released a security advisory for CVE-2026-16675 affecting FactoryTalk Activation Manager V5.02 and below, a privilege escalation vulnerability with a CVSS score of 7.8. An authenticated attacker with Windows credentials could hijack console windows spawned during installation or repair to obtain SYSTEM-level command access. The vendor recommends updating to version V5.03.

Why it matters: Manufacturing organizations worldwide using FactoryTalk Activation Manager V5.02 or earlier face privilege escalation risk during system installation or repair; immediate patching to V5.03 is required to prevent local attackers from gaining full system control on critical infrastructure assets.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary