Vulnerabilities & Exploits

Manufacturing Message Flows Can Be Hijacked via Artemis

The risk is not a broker crash. An unauthenticated attacker on the adjacent network can coerce Opcenter RDnL’s ActiveMQ Artemis broker into federating with a rogue broker, then use that path to inject or divert messages feeding manufacturing workflows.

CISA and Siemens tie CVE-2026-27446 to Opcenter RDnL and say the issue affects environments that allow inbound Core connections from untrusted sources and outbound Core connections to untrusted targets. Siemens says all Opcenter RDnL versions are affected, and ActiveMQ Artemis has released a new version; the advisory does not give a Siemens fix version.

The forward risk is corrupted queue state, not just service loss. In OT settings, that can distort downstream control and production messaging even when the broker host itself stays up.

1 source · May 14

CVE-2026-27446

NVD KEV

CVSS 9.8 CRITICAL: missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. EPSS 10% (95th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-05-14

Every edition of this story: Manufacturing Message Flows Can Be Hijacked via Artemis

More from today