CVE-2026-27446
CVSS 9.8 CRITICAL: missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. EPSS 10% (95th percentile).
Vulnerabilities · 124 days ago
The risk is not a broker crash. An unauthenticated attacker on the adjacent network can coerce Opcenter RDnL’s ActiveMQ Artemis broker into federating with a rogue broker, then use that path to inject or divert messages feeding manufacturing workflows.
CISA and Siemens tie CVE-2026-27446 to Opcenter RDnL and say the issue affects environments that allow inbound Core connections from untrusted sources and outbound Core connections to untrusted targets. Siemens says all Opcenter RDnL versions are affected, and ActiveMQ Artemis has released a new version; the advisory does not give a Siemens fix version.
The forward risk is corrupted queue state, not just service loss. In OT settings, that can distort downstream control and production messaging even when the broker host itself stays up.
CVSS 9.8 CRITICAL: missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. EPSS 10% (95th percentile).
1 source covering this story
Siemens Opcenter RDnL Summary Opcenter RDnL is affected by missing authentication in critical function in ‘ActiveMQ Artemis’.
Part of the PlainSec briefing for 2026-05-14