Source context: this article examines information published by the source on September 01, 2026. This site’s publication date is shown separately. Check the latest vendor guidance before acting.
What the vulnerability is
CVE-2026-16675 is a privilege escalation vulnerability affecting Rockwell Automation FactoryTalk Activation Manager. The flaw originates from custom actions within the software installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations.
An authenticated attacker possessing Windows credentials can hijack these active console windows to launch a SYSTEM-level command prompt. This provides the attacker with full access to system resources, processes, and files on the affected host.
Exposure and applicability
This vulnerability applies to installations of FactoryTalk Activation Manager version V5.02 and all versions prior. The risk is most acute during active installation or repair cycles where the installer’s custom actions are triggered. Because this requires an authenticated attacker with local Windows credentials, the exposure is primarily focused on internal threats or attackers who have already established a foothold on the workstation.
Remediation priorities
Our analysis suggests prioritizing remediation based on the criticality of the workstation hosting the activation manager and the level of access granted to local users.
- Update Software: The primary corrective action is updating FactoryTalk Activation Manager to version V5.03, which addresses the flaw in the installer’s custom actions.
- Restrict Local Access: For systems where an immediate update is not feasible, reducing the number of users with authenticated access to the host can limit the pool of potential attackers capable of hijacking the console windows.
- Apply General Security Hardening: Following vendor-recommended security best practices for industrial control system environments may provide compensating layers of defense.
How to validate remediation
To verify that exposure has been reduced, vulnerability management teams should perform the following:
- Version Verification: Confirm that the installed version of FactoryTalk Activation Manager is V5.03 or higher.
- Installation Audit: Ensure that no legacy versions (V5.02 and below) remain on the system from previous failed updates or side-by-side installations.
It is important to note that a version check confirms the presence of the fix but does not independently prove that the system is secure from other vectors.
Limits and open questions
While updating to V5.03 addresses the specific mechanism described in CVE-2026-16675, residual risk remains if other local privilege escalation paths exist on the underlying Windows operating system. The source does not specify if there are alternative methods for triggering these console windows outside of standard installation or repair operations. Additionally, while no public exploitation has been reported to CISA, the inherent nature of SYSTEM-level access makes this a high-priority item for infrastructure owners.
Source and editorial note
Rockwell Automation FactoryTalk Activation Manager · Source date: September 01, 2026 · Retrieved September 01, 2026.
Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.
Request a Vulnerability Assessment
Turn security intelligence into action.
Discuss your exposure, priorities, and the evidence needed to validate the outcome.
Request a security assessment ↗