
Rockwell Automation FactoryTalk DataMosaix
A vulnerability in Rockwell Automation’s FactoryTalk DataMosaix Private Cloud (versions 8.02 and earlier) allows authenticated attackers to inject malicious scripts due to improper input neutralization. This issue, classified as a stored cross-site scripting vulnerability (CVE-2026-9292), could lead to account takeovers and credential theft. Users are urged to upgrade to version 8.03 or later. CISA advises enhancing network security and following best practices to mitigate risks, with no known active exploitation reported.










