Vulnerabilities & Exploits

Armatura One’s Embedded Broker Widens the Blast Radius

CISA says Armatura One has five CVEs, including KEV-listed CVE-2023-46604, and affects versions below 4.7.2 and 4.6.1_USA. The advisory says successful exploitation can expose the database, execute code on the host at highest privilege, or let an attacker control the physical access-control system it manages.

The key detail is that Armatura One ships with Apache ActiveMQ listening on the network by default. That broker can be reached before login is checked, and CVE-2023-46604 lets a network attacker feed it data that gets treated as objects, which can turn into code execution on the host; CISA also says credentials stored in the install config can be recovered and decrypted under CVE-2026-94591.

For operators in communications, manufacturing, energy, and transportation, this is more than an app patch: the hidden broker and the access-control role mean a compromise can cross from software into doors, badges, and other physical controls. The exposure that matters after the fix is any deployment where the product still fronts real-world access systems or bundles other reachable backend services.

1 source · 9h ago

CVE-2023-46604

NVD KEV

Known exploited · CISA KEV

CVSS 10 CRITICAL: the Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. Known ransomware campaign use. EPSS 100% (100th percentile).

CISA federal remediation date Nov 23 · date passed

CVE-2026-94591

NVD KEV

CVE-2026-94592

NVD KEV

CVE-2026-94593

NVD KEV

CVE-2026-94594

NVD KEV

Timeline

Sources

Part of the PlainSec briefing for 2026-10-01

Every edition of this story: Armatura One’s Embedded Broker Widens the Blast Radius

More from today