← Back

Wire · regulatory

Rockwell Automation FactoryTalk Services Platform

Published

21 July 2026

Topic

regulatory

Sectors

CybersecurityIndustrial Automation

Geography

United States

Source

Read at cisa.gov

Verified

Fusion42 · 21 July 2026 · Fusion42 review

Rockwell Automation FactoryTalk Services Platform (FTSP) 6.60 contains a critical authentication bypass vulnerability (CVE-2026-10714) that allows low-privilege attackers to forge JWT tokens and impersonate any authorized user, gaining access to system configurations and permission management across FTSP-protected systems. CISA rates the vulnerability HIGH severity (CVSS 7.8-8.8) but notes no known public exploitation yet.

This Wire brief sits within Fusion42's coverage of Cybersecurity and Industrial Automation.

◆ The Wire takeaway

If you sell defence-in-depth tools to manufacturing plants—detection, segmentation, or identity—Rockwell just handed you a use case: every FTSP deployment is now a known weak link that can't be patched away overnight, and buyers will be hunting for compensating controls. Your pitch window is open until patches ship.

Coverage

1 source · 21 Jul 2026

Related on Wire

Topics

CybersecurityIndustrial Automationcritical-manufacturingjwt-auth-bypassics-securitycisa-advisoryaccess-control