Rockwell Automation recommends upgrading to software version V5.03. For organizations unable to upgrade immediately, follow security best practices: minimize network exposure for control system devices, ensure systems are not internet-facing, locate control system networks behind firewalls and isolate them from business networks, and use secure remote access methods such as VPNs when required. No known public exploitation has been reported to CISA at the time of the advisory.
Quick answers
What is CVE-2026-16675?
Rockwell Automation recommends upgrading to software version V5.03. For organizations unable to upgrade immediately, follow security best practices: minimize network exposure for control system devices, ensure systems are not internet-facing, locate control system networks behind firewalls and isolate them from business networks, and use secure remote access methods such as VPNs when required. No known public exploitation has been reported to CISA at the time of the advisory.
How severe is CVE-2026-16675?
high, CVSS 8.5
Is CVE-2026-16675 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-16675 be mitigated?
Rockwell Automation recommends upgrading to software version V5.03. For organizations unable to upgrade immediately, follow security best practices: minimize network exposure for control system devices, ensure systems are not internet-facing, locate control system networks behind firewalls and isolate them from business networks, and use secure remote access methods such as VPNs when required. No known public exploitation has been reported to CISA at the time of the advisory.
CVSS
8.5
Vendor
Rockwell Automation
Published
Sep 30, 2026 · 08:42
Patch
Unknown / not confirmed
Affected products
FactoryTalk Activation Manager
Mitigation
Rockwell Automation recommends upgrading to software version V5.03. For organizations unable to upgrade immediately, follow security best practices: minimize network exposure for control system devices, ensure systems are not internet-facing, locate control system networks behind firewalls and isolate them from business networks, and use secure remote access methods such as VPNs when required. No known public exploitation has been reported to CISA at the time of the advisory.
The US Cybersecurity and Infrastructure Security Agency (CISA) has issued an Industrial Control Systems advisory (ICSA-26-244-04) disclosing a privilege escalation vulnerability in Rockwell Automation FactoryTalk Activation Manager. The flaw, tracked as CVE-2026-16675, stems from custom installer actions that spawn visible console windows running with SYSTEM privileges during installation or repair. An authenticated attacker in possession of Windows credentials could hijack these consoles to obtain a SYSTEM-level command prompt, potentially achieving full system compromise. Rockwell Automation recommends upgrading to version V5.03. No known public exploitation has been reported to CISA at the time of the advisory.