On July 16, 2026, CISA released ICS Advisory ICSA-26-197-09 identifying a successful exploitation path in Rockwell Automation FactoryTalk DataMosaix: authenticated attackers can inject malicious scripts on affected servers. According to the official CISA advisory and supporting CSAF documentation, this vulnerability requires valid credentials—a critical constraint that limits immediate exposure but does not eliminate risk in environments where access controls have been compromised or insider threats exist.
Rockwell Automation FactoryTalk DataMosaix is a common industrial data integration and analytics platform used across manufacturing, energy, water, and chemical processing sectors. Script injection vulnerabilities in OT (operational technology) environments are particularly dangerous because they can allow attackers to manipulate real-time sensor data, alter process parameters, or exfiltrate control logic without triggering conventional IT security alerts.
The advisory confirms affected versions but detailed patch availability and specific version scope require review of the full CSAF file referenced in the official CISA notice. This staged disclosure pattern—advisory issued before comprehensive patch availability—suggests either a coordinated disclosure window or ongoing vendor patch development.
For organizations running FactoryTalk DataMosaix, the authentication requirement means the primary risk vectors are compromised user accounts, privilege escalation, or lateral movement from breached IT systems into OT networks. This vulnerability also signals a broader pattern: industrial automation platforms are increasingly targeted for data manipulation attacks rather than outright shutdown—a shift that makes detection harder and impacts product quality, safety compliance, and supply chain integrity before any system-level failure occurs.
The low severity rating reflects the authentication gate, but severity alone does not equal impact in critical infrastructure contexts. A single compromised service account in a petrochemical facility or grid operations center could enable persistent manipulation of control data with minimal forensic signature.

