
🚨 #ALERT — ARMATURA ONE SHIPS AN EMBEDDED ACTIVEMQ RCE PATH AFFECTING PHYSICAL ACCESS CONTROL October 1, 2026 DISCLOSED BY: CISA / Armatura LLC PRODUCT: Armatura One — Physical Access Control System CVE: CVE-2023-46604 — CVSS 9.8 CVE-2026-94591 CVE-2026-94592 CVE-2026-94593 CVE-2026-94594 AFFECTED VERSIONS: Armatura One <4.7.2 Armatura One USA <4.6.1_USA IMPACT: CISA states that Armatura One embeds an Apache ActiveMQ version affected by CVE-2023-46604 and exposes its OpenWire listener on the network by default. An unauthenticated network attacker can trigger deserialization before authentication is checked, potentially achieving arbitrary code execution with the highest privilege on the host operating system. Additional Armatura flaws expose fixed cryptographic material, hard-coded database credentials and plaintext credentials in logs. CISA states that successful exploitation of the vulnerability set could result in unauthorized database access or control of the physical access-control system. EXPLOITATION STATUS: NO CONFIRMED ARMATURA-SPECIFIC IN-THE-WILD EXPLOITATION. IMPORTANT: CVE-2023-46604 is already in CISA KEV for Apache ActiveMQ and has known ransomware-campaign use. This does NOT establish ransomware exploitation of Armatura One itself. CISA explicitly states it is not aware of exploitation specifically targeting Armatura One in relation to these vulnerabilities. knownRansomwareCampaignUse: Known — for the underlying Apache ActiveMQ CVE-2023-46604 generally, not specifically Armatura One. Forensic triage: No Armatura-specific IoCs are published in the CISA advisory. Review untrusted-network exposure of the OpenWire listener, anomalous broker connections, unexpected database/message-broker credential use, and preserve application and infrastructure logs before remediation where exposure existed. URGENT ACTION: Upgrade Armatura One to 4.7.2+. For the USA release line, upgrade to 4.6.1_USA+. Minimize network exposure, place control systems behind firewalls and isolate them from business networks as recommended by CISA. SOURCE: https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01 CISA: https://www.cisa.gov/known-exploited-vulnerabilities-catalog BACKUP: https://raw.githubusercontent.com/cisagov/kev-data/develop/known_exploited_vulnerabilities.json?utm_source=chatgpt.com CONFIDENCE: VERY HIGH for the RCE path, affected versions and technical impact — directly documented by CISA. INSUFFICIENT for any claim of Armatura-specific active exploitation. #CyberSecurity #ThreatIntel #NØØT #Armatura #ArmaturaOne #RCE #ActiveMQ #PhysicalSecurity #AccessControl #OTSecurity #CriticalInfrastructure #ICS #Ransomware #CVE_2023_46604
