Hitachi Energy SOI
View CSAF Summary Hitachi Energy is aware of RCE (Remote Code Execution) vulnerability in Apache ActiveMQ component of SOI product versions listed in this document. These vulnerabilities can be exploited to carry out various attacks affecting confidentiality, integrity, and availability of the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The…
Excerpt from the primary source: CISA Cybersecurity Advisories
Who is affected
Developers · Critical infrastructure
Affected technology: ActiveMQ
Why it matters
CISA lists this as exploited in the wild. Unpatched ActiveMQ systems are exposed to active attacks now.
Automated: stated only from CISA listings and the exploitation evidence in the sources below.
What you should do · Mitigate
No complete fix is indicated yet. Apply the vendor's recommended workarounds for ActiveMQ, limit exposure (for example, restrict internet access to management interfaces) and watch for a patch.
CISA's required action for CVE-2026-34197: "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable." US federal civilian agencies must comply by April 30, 2026.
Automated guidance based on this story's classification. Check the linked advisories for specifics.
Sources
We link to original and authoritative sources. Headlines and excerpts belong to their publishers.
Government advisory
Related
Armatura LLC Armatura One
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-control system. The following versions of Armatura LLC Armatura One are affected: Armatura One <4.7.2 (CVE-2023-46604, CVE-2026-94591, CVE-2026-94592, CVE-2026-94593…
CISA lists this as exploited in the wild and known to be used in ransomware campaigns. Unpatched ActiveMQ systems are exposed to active attacks now.
Treat this as an emergency.
'BigDiskBuster' Leaves Microsoft Defender Running While Blocking Updates
Not quite an EDR-killer, but the proof-of-concept cyber technique creates a silent virus detection gap while service runs normally, no exploit required.
Johnson Controls EasyIO FG
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain full unauthorized access to the device. The following versions of Johnson Controls EasyIO FG are affected: EasyIO FG firmware <=2.0b52 (CVE-2026-27872, CVE-2026-27873) CVSS Vendor Equipment v3 7.7 Johnson Controls EasyIO FG firmware 2 Vulnerabilities Use of Hard-coded Credentials, Improper Privilege…
Savannah lwIP SMTP client
View CSAF Summary Successful exploitation of this vulnerability could crash the device being accessed; a buffer overflow condition may allow remote code execution. The following versions of Savannah lwIP SMTP client are affected: lwIP SMTP client 2.2.1 (CVE-2026-15340) CVSS Vendor Equipment v3 9.8 Savannah lwIP SMTP client 1 Vulnerability Buffer Copy without Checking Size of Input ('Classic Buffer…
