Severity: HighAction: MitigateExploitation: ExploitedCISA KEV

Hitachi Energy SOI

View CSAF Summary Hitachi Energy is aware of RCE (Remote Code Execution) vulnerability in Apache ActiveMQ component of SOI product versions listed in this document. These vulnerabilities can be exploited to carry out various attacks affecting confidentiality, integrity, and availability of the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The…

Excerpt from the primary source: CISA Cybersecurity Advisories

Who is affected

Developers · Critical infrastructure

Affected technology: ActiveMQ

Why it matters

CISA lists this as exploited in the wild. Unpatched ActiveMQ systems are exposed to active attacks now.

Automated: stated only from CISA listings and the exploitation evidence in the sources below.

What you should do · Mitigate

No complete fix is indicated yet. Apply the vendor's recommended workarounds for ActiveMQ, limit exposure (for example, restrict internet access to management interfaces) and watch for a patch.

CISA's required action for CVE-2026-34197: "Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable." US federal civilian agencies must comply by April 30, 2026.

Automated guidance based on this story's classification. Check the linked advisories for specifics.

Sources

We link to original and authoritative sources. Headlines and excerpts belong to their publishers.

Government advisory

Hitachi Energy SOI CISA Cybersecurity Advisories · cisa.gov · Oct 6, 2026 · Primary source
Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

Armatura LLC Armatura One

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-control system. The following versions of Armatura LLC Armatura One are affected: Armatura One <4.7.2 (CVE-2023-46604, CVE-2026-94591, CVE-2026-94592, CVE-2026-94593…

Why it matters

CISA lists this as exploited in the wild and known to be used in ransomware campaigns. Unpatched ActiveMQ systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Severity: ElevatedAction: Be aware

Johnson Controls EasyIO FG

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain full unauthorized access to the device. The following versions of Johnson Controls EasyIO FG are affected: EasyIO FG firmware <=2.0b52 (CVE-2026-27872, CVE-2026-27873) CVSS Vendor Equipment v3 7.7 Johnson Controls EasyIO FG firmware 2 Vulnerabilities Use of Hard-coded Credentials, Improper Privilege…

Severity: HighAction: Review

Savannah lwIP SMTP client

View CSAF Summary Successful exploitation of this vulnerability could crash the device being accessed; a buffer overflow condition may allow remote code execution. The following versions of Savannah lwIP SMTP client are affected: lwIP SMTP client 2.2.1 (CVE-2026-15340) CVSS Vendor Equipment v3 9.8 Savannah lwIP SMTP client 1 Vulnerability Buffer Copy without Checking Size of Input ('Classic Buffer…