CISA warns of critical Armatura One vulnerabilities
A CISA advisory dated October 1, 2026, reports risks of code execution, unauthorized access, and credential exposure in Armatura One. The stated severity reaches CVSS 9.8.
A CISA advisory published on October 1, 2026, says Armatura One and Armatura One (USA) are affected by vulnerabilities. Exploitation could enable unauthorized database access, code execution on the host with maximum privileges, or takeover of the physical access-control system. The advisory cites critical-infrastructure sectors and worldwide deployment; its CVSS 3.1 score is 9.8, critical.
The issues described include CVE-2023-46604, involving deserialization in network-exposed Apache ActiveMQ/OpenWire, and CVE-2026-94591, involving credentials protected with a fixed key and initialization vector embedded in the software. The text also mentions hard-coded credentials and sensitive information in logs, but the available excerpt does not provide full details for every flaw. Armatura advises contacting its official technical support to obtain and apply the update. Consult the original CISA advisory and its CSAF summary to verify scope, versions, and current instructions.