CVE-2026-27446
CVSS 9.8 CRITICAL: missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. EPSS 1% (65º percentile).
Vulnerabilità ed exploit
Il rischio non è un crash del broker. Un attacker non autenticato sulla rete adiacente può costringere il broker ActiveMQ Artemis di Opcenter RDnL a federarsi con un rogue broker, quindi usare quel percorso per iniettare o deviare i messaggi che alimentano i workflow di produzione.
1 fonte · 14 mag
CVSS 9.8 CRITICAL: missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. EPSS 1% (65º percentile).
CISA Advisories
Siemens Opcenter RDnL | CISA
Siemens Opcenter RDnL Summary Opcenter RDnL is affected by missing authentication in critical function in ‘ActiveMQ Artemis’.
originalePart of the PlainSec briefing for 2026-05-14
Every edition of this story: I flussi di messaggistica industriale possono essere dirottati tramite Artemis