CISA Advisories Privilege Escalation Flaw in Rockwell Automation FactoryTalk Activation Manager
CVE-2026-16675 affects versions V5.02 and below; authenticated attacker could attain SYSTEM-level access
Key Takeaways
- CISA advisory ICSA-26-244-04 discloses privilege escalation vulnerability CVE-2026-16675 in Rockwell Automation FactoryTalk Activation Manager versions V5.02 and below.
- The flaw stems from installer custom actions that spawn visible console windows running with SYSTEM privileges; an authenticated attacker with Windows credentials could hijack these consoles to attain SYSTEM-level access.
- CVSS scores range from 7.8 (v3) to 8.5 (v4.0), reflecting HIGH severity.
- Rockwell Automation recommends upgrading to version V5.03 as the primary remediation.
Related Security News
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.


