<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:rockwellautomation:factorytalk_activation_manager:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3arockwellautomationfactorytalk_activation_manager/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 01 Sep 2026 17:11:21 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3arockwellautomationfactorytalk_activation_manager/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Privilege Escalation Vulnerability in Rockwell Automation FactoryTalk Activation Manager</title><link>https://feed.craftedsignal.io/briefs/2026-09-rockwell-activation-manager-privesc/</link><pubDate>Tue, 01 Sep 2026 17:11:21 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-rockwell-activation-manager-privesc/</guid><description>Rockwell Automation FactoryTalk Activation Manager versions V5.02 and below are vulnerable to local privilege escalation via insecure installer custom actions that spawn SYSTEM-level console windows.</description><content:encoded><![CDATA[<p>Rockwell Automation FactoryTalk Activation Manager versions V5.02 and below are susceptible to a privilege escalation vulnerability tracked as CVE-2026-16675. The flaw originates from custom actions implemented within the software's installer process. During installation or repair operations, these custom actions spawn visible console windows that operate with SYSTEM-level privileges. An attacker who has already achieved local access on a Windows system can interact with or hijack these exposed console windows to execute arbitrary commands with SYSTEM permissions. This vulnerability is particularly critical in industrial environments where the affected management software may be present on engineering workstations or server infrastructure, potentially granting an attacker full control over the host OS. The vendor has released version V5.03 to address this security defect.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows a local authenticated user to gain full SYSTEM privileges on the affected host. This provides the attacker with total control over system processes, sensitive files, and configuration data. The impact is significant for industrial environments where engineering workstations could be compromised, potentially facilitating lateral movement into sensitive operational technology networks.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security and IT teams:</p>
<ul>
<li>Upgrade all instances of Rockwell Automation FactoryTalk Activation Manager to version V5.03 or later immediately to patch CVE-2026-16675.</li>
<li>Audit industrial workstations for installations of FactoryTalk Activation Manager V5.02 and below to prioritize remediation.</li>
<li>Implement restrictive access controls for users on machines running industrial management software to limit the scope of potential local exploitation.</li>
<li>Use the provided Sigma rule to detect suspicious console window activity spawned by installation processes during software maintenance windows.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>privilege-escalation</category><category>industrial-control-systems</category><category>windows</category><category>ics</category></item></channel></rss>