Executive Summary

CVE-2026-16675 is an improper restriction of excessive authentication attempts in Rockwell Automation FactoryTalk Activation Manager version 5.02 and below, carrying a vendor CVSS v3 score of 7.8. The flaw removes the throttling that should stop credential guessing against the software licensing layer, and because Activation Manager governs whether HMI, historian, and control applications remain licensed and operational, a compromise here can strip production authority from a running plant.

Technical Exposure Breakdown

The vulnerable component is the authentication interface of FactoryTalk Activation Manager, the service that manages concurrent and node-locked licenses across a Rockwell software estate. The weakness class is CWE-307, improper restriction of excessive authentication attempts. In practical terms the service accepts an unbounded or insufficiently rate limited number of login attempts, which permits automated brute force or credential stuffing against valid accounts.

The attack vector depends on where Activation Manager is deployed. In many sites it runs on an engineering workstation or a dedicated license server reachable across the OT segment. Any actor with network line of sight to that host, or with a foothold on a peer workstation, can iterate credentials without lockout. The CVSS 7.8 vector suggests a local or adjacent attack path rather than a raw internet exposure, which is consistent with how license infrastructure sits inside plant networks rather than on perimeter edges. That does not lower the concern. Lateral movement inside flat OT VLANs is the normal case, not the exception.

The precondition for exploitation is reachability plus a target account. Where operators reuse a shared administrative credential across the FactoryTalk stack, a single guessed password can cascade into broader access. Patch status for this CVE is not confirmed in the available data, so operators should treat this as an unresolved exposure and plan around it.

OT Impact and Compliance Risk

The physical risk is indirect but real. Activation Manager does not move a valve or trip a breaker. It decides whether the software that moves valves and trips breakers stays authorized to run. An attacker who gains control of the licensing service can revoke, exhaust, or corrupt activations, which can force HMI clients, batch servers, or SCADA components into grace period or shutdown states. In a continuous process that translates to loss of view and loss of control at the exact moment operators most need both.

For IEC 62443 aligned programs this hits system integrity and access control requirements under SR 1.x and the identification and authentication family directly. The absence of authentication attempt limiting is a documented gap against SR 1.11. For NERC CIP registered entities running Rockwell software in a BES Cyber System, this maps to CIP-007 system security management, specifically account and access controls, and to CIP-005 electronic security perimeter assumptions if the license host is reachable from outside a defined zone. Pipeline operators under TSA SD-02C should log this against their access control and segmentation measures. Water and wastewater utilities operating under AWIA 2018 risk and resilience obligations should note that Rockwell software is common in treatment SCADA and that this exposure belongs in the next assessment cycle.

Compensating Controls

Do not wait for a patch you cannot confirm exists. Isolate the Activation Manager host into a tightly scoped zone and restrict inbound access to only the specific workstations and servers that require licensing checkouts. Enforce host firewall rules that limit source addresses to that allowlist.

Implement authentication attempt limiting externally where the application will not. A reverse proxy or host based control that counts failed attempts per source and applies a lockout window recreates the missing throttle. Rotate any shared credentials to unique per host accounts and remove default or dormant logins.

For virtual patching, deploy a Suricata rule concept that watches the license service port for a high frequency of authentication requests from a single source within a short window and alerts on threshold breach, for example more than ten attempts in sixty seconds. Tune the count to your normal checkout cadence to avoid false positives during legitimate startup storms. Passive detection is the right posture here. Active scanning of a live license server risks disrupting checkouts and can knock dependent applications into unlicensed states, so keep discovery to passive traffic analysis and asset inventory data you already hold.

BreachSpider Intel

BreachSpider tracks CVE-2026-16675 and the broader Rockwell FactoryTalk exposure surface so OT teams can monitor advisory revisions, exploitation signals, and affected version movement without active scanning against fragile control assets.