CISA has published ICS advisory ICSA-26-274-01 covering a cluster of critical vulnerabilities in Armatura LLC's Armatura One, a physical access-control platform deployed in commercial, industrial, and critical-infrastructure environments. The advisory carries a CVSS v3 score of 9.8 (Critical) — and unlike many ICS advisories that require adjacent network access or complex exploitation chains, this one is brutally straightforward: successful exploitation could allow an attacker to gain unauthorized access to the backend database, execute arbitrary code on the host with the highest level of privilege, or take control of the physical access-control system itself.
Let that sink in. This is not a data-loss scenario. This is an attacker remotely unlocking doors, disabling badge logging, or manipulating audit trails of who entered which facility and when. In my 15 years of IR work, the convergence of cyber and physical access is where incidents stop being "security events" and start being safety events.
Affected versions:
- Armatura One < 4.7.2 (all CVEs below)
- Armatura One (USA) < 4.6.1 (all CVEs below)
CVEs covered: CVE-2026-94591, CVE-2026-94592, CVE-2026-94593, CVE-2026-94594, and CVE-2023-46604 — the latter being a legacy deserialization flaw still shipped in the product's bundled components, now formally called out in this 2026 advisory and assessed as exploitable in this deployment context.
If you operate Armatura One panels or management servers, this is a patch-this-week advisory.
Technical Analysis
The Vulnerability Stack
The advisory maps to four distinct weakness classes, and the combination is what makes this so dangerous:
| CVE | Weakness | Defender Impact |
|---|---|---|
| CVE-2023-46604 | Deserialization of Untrusted Data | Remote code execution via the bundled ActiveMQ OpenWire connector (default TCP/61616). An unauthenticated attacker can instantiate arbitrary classes via serialized payloads, leading to code execution in the service context. |
| CVE-2026-94591 | Use of Hard-coded Cryptographic Key | A static key embedded in the product allows any attacker with access to the firmware/software to decrypt protected data or forge trusted communications across any deployment — keys are not per-customer. |
| CVE-2026-94592 | Use of Hard-coded Credentials | Embedded, non-customer-changeable credentials provide direct authenticated access to the application or its database. This defeats password rotation as a compensating control. |
| CVE-2026-94593 | Insertion of Sensitive Information into Log File | Credentials, keys, or session material written to application logs in cleartext — turning every log aggregation pipeline, backup, and SIEM into a credential store for anyone with read access. |
| CVE-2026-94594 | (Chained access-control compromise) | Enables escalation from application access to full control of the physical access-control system: door states, schedules, cardholder records, and audit logs. |
Why the Chain Matters More Than Any Single CVE
From a defender's perspective, the attack chain practically writes itself:
- Recon: Attacker identifies exposed Armatura One management interfaces or the bundled message broker (ActiveMQ OpenWire on 61616) via Shodan/Censys or internal lateral movement.
- Initial access: Hard-coded credentials (CVE-2026-94592) or the hard-coded cryptographic key (CVE-2026-94591) grant authenticated access without any exploit development.
- Execution: Where auth fails, the deserialization flaw (CVE-2023-46604) delivers unauthenticated RCE — typically observed as the Java/ActiveMQ process spawning shell commands to download and execute payloads.
- Collection: Cleartext secrets in application logs (CVE-2026-94593) enable credential harvesting and persistence — including credentials for systems adjacent to Armatura.
- Impact: Full control of door controllers, badge records, and audit logs (CVE-2026-94594), with code execution at the highest privilege level on the host.
Exploitation Status
As of this writing, CISA has not listed these CVEs in the Known Exploited Vulnerabilities (KEV) catalog, and no public in-the-wild exploitation has been confirmed in the advisory. However, three factors dramatically compress your remediation window:
- CVE-2023-46604 has a long history of public PoCs and mass exploitation against ActiveMQ — weaponized exploit code is trivially available, and its presence in this product is now publicly documented.
- Hard-coded credential/key disclosures are zero-skill exploits. Once researchers or threat actors extract the values from the software (which is now guaranteed, given the advisory), exploitation requires nothing more than logging in.
- Physical access control systems are high-value, low-monitoring targets. They sit on OT-adjacent VLANs with little endpoint telemetry and are rarely in the vulnerability scan scope.
Treat this as exploitable-today, not theoretical.
Detection & Response
The detections below target the observable behaviors of this chain: ActiveMQ OpenWire exposure, deserialization-style child process execution from the service, and access to Armatura log files that now contain sensitive material.
Sigma Rules
---
title: Armatura One / ActiveMQ Service Spawning Shell or Script Interpreter
id: 4c8f2a61-9b3d-4e7a-bf21-8d5c6a0e9f12
status: experimental
description: Detects the Armatura One service or its bundled ActiveMQ/Java process spawning command shells or script interpreters, consistent with CVE-2023-46604 deserialization RCE exploitation.
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01
- https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/09/30
tags:
- attack.execution
- attack.t1059
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\java.exe'
- '\javaw.exe'
- '\activemq.exe'
- '\wrapper.exe'
ParentCommandLine|contains:
- 'activemq'
- 'armatura'
selection_child:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\mshta.exe'
- '\rundll32.exe'
- '\certutil.exe'
- '\bitsadmin.exe'
condition: selection_parent and selection_child
falsepositives:
- Rare legitimate maintenance scripts invoked by the application; validate against change windows
level: critical
---
title: Inbound Network Connection to ActiveMQ OpenWire Port 61616
id: 7e2b9c44-1a5f-4d38-9c6e-2f7a1b8d3e05
status: experimental
description: Detects inbound network connections to the ActiveMQ OpenWire listener (TCP 61616) bundled with Armatura One, the exploitation vector for CVE-2023-46604 deserialization. Baseline expected broker clients before deployment.
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01
- https://attack.mitre.org/techniques/T1190/
author: Security Arsenal
date: 2026/09/30
tags:
- attack.initial_access
- attack.t1190
logsource:
category: network_connection
product: windows
detection:
selection:
DestinationPort: 61616
Initiated: 'false'
filter_local:
SourceIp|startswith:
- '10.'
- '192.168.'
condition: selection and not filter_local
falsepositives:
- Internal broker clients if Armatura documentation confirms 61616 usage in your deployment — baseline and allowlist known controller IPs
level: high
---
title: Suspicious Read Access to Armatura One Application Log Files
id: 2f6a1d83-5c4e-4b29-8a17-6e3d9c0b7f41
status: experimental
description: Detects processes outside the Armatura application stack reading its application log files, which may contain cleartext credentials or keys per CVE-2026-94593. Adjust the log path to your installation directory.
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01
- https://attack.mitre.org/techniques/T1552/
author: Security Arsenal
date: 2026/09/30
tags:
- attack.credential_access
- attack.t1552.001
logsource:
category: file_event
product: windows
detection:
selection:
TargetFilename|contains:
- '\Armatura\logs\'
- '\ArmaturaOne\logs\'
- '\Armatura One\logs\'
filter_app:
Image|contains:
- '\Armatura\'
- '\ArmaturaOne\'
filter_backup:
Image|endswith:
- '\backup.exe'
- '\Veeam.Backup.Service.exe'
condition: selection and not filter_app and not filter_backup
falsepositives:
- Backup agents, SIEM forwarders, and EDR scanners — allowlist by process hash, not path
level: medium
KQL (Microsoft Sentinel / Defender)
This query hunts across both endpoint telemetry (Defender) and network/syslog ingestion (Sentinel) for the two highest-signal behaviors: child processes of the Armatura/ActiveMQ service, and network sessions to the OpenWire broker port.
// Hunt 1: Deserialization-style child process execution from Armatura/ActiveMQ service
let SuspiciousChildren = dynamic(["cmd.exe","powershell.exe","pwsh.exe","mshta.exe","wscript.exe","cscript.exe","rundll32.exe","certutil.exe","curl.exe","wget.exe"]);
DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where InitiatingProcessCommandLine has_any ("activemq","armatura")
or InitiatingProcessFileName in~ ("java.exe","javaw.exe","wrapper.exe")
| where FileName in~ (SuspiciousChildren)
| project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, FileName, ProcessCommandLine, AccountName
| order by TimeGenerated desc;
// Hunt 2: Inbound connections to ActiveMQ OpenWire (61616) on Armatura hosts
DeviceNetworkEvents
| where TimeGenerated > ago(14d)
| where LocalPort == 61616
| where not (RemoteIP startswith "10." and RemoteIPType == "Private") // tune to your controller subnet allowlist
| summarize Connections = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated), SourceIPs = make_set(RemoteIP) by DeviceName, LocalIP, RemotePort
| order by Connections desc;
// Hunt 3: Syslog/CEF-ingested firewall or ICS sensor hits against 61616 from non-controller sources
CommonSecurityLog
| where TimeGenerated > ago(14d)
| where DestinationPort == 61616
| summarize by SourceIP, DestinationIP, DeviceAction, DeviceVendor, TimeGenerated
| order by TimeGenerated desc;
Velociraptor VQL
For DFIR triage of a suspected Armatura One host — enumerate the broker listener, its owning process, and any child processes that should not exist.
-- Identify the process listening on ActiveMQ OpenWire (61616) and its children
LET listener = SELECT Pid, Name, Path, Laddr, Status
FROM netstat()
WHERE Laddr =~ ':61616'
SELECT Pid, Name, CommandLine, Exe, Username, CreateTime,
Ppid
FROM pslist()
WHERE Pid IN (SELECT Pid FROM listener)
OR Ppid IN (SELECT Pid FROM listener)
OR CommandLine =~ '(?i)activemq|armatura'
-- Separately: locate Armatura log files that may contain cleartext secrets (CVE-2026-94593)
SELECT FullPath, Size, Mtime
FROM glob(globs=['C:/Program Files*/Armatura*/logs/*.log',
'C:/Armatura*/logs/*.log'])
ORDER BY Mtime DESC
Remediation & Verification Script
Run on the Armatura One management server (or via your RMM against all identified hosts) to inventory version, exposure, and risky artifacts. Bash variant covers Linux-based deployments; adapt paths to your installation.
#!/bin/bash
# Armatura One exposure audit — ICSA-26-274-01
echo "=== Armatura One Exposure Audit ==="
echo "[1] Installed version (check against fixed: 4.7.2 / 4.6.1-USA):"
grep -ri "version" /opt/armatura*/config/ 2>/dev/null | head -5
ls -d /opt/armatura* /usr/local/armatura* 2>/dev/null
echo "[2] Is OpenWire 61616 listening? (CVE-2023-46604 vector):"
ss -tlnp | grep -E ':61616' || echo " OK - 61616 not listening"
echo "[3] Web/management interfaces exposed on all interfaces (0.0.0.0):"
ss -tlnp | grep '0.0.0.0' | grep -iE 'java|armatura|wrapper'
echo "[4] Log files that may contain cleartext secrets (CVE-2026-94593):"
find /opt/armatura* /usr/local/armatura* -name '*.log' -type f 2>/dev/null | while read f; do
hits=$(grep -icE 'password|secret|key=|credential' "$f" 2>/dev/null)
[ "$hits" -gt 0 ] && echo " REVIEW: $f ($hits matches)"
done
echo "[5] Java/ActiveMQ child shell executions (last 200 syslog lines):"
grep -iE 'activemq|armatura' /var/log/syslog 2>/dev/null | grep -iE 'cmd|/bin/sh|/bin/bash|curl|wget' | tail -20
echo "[6] Host firewall - block 61616 from non-controller subnets (review before applying):"
echo " iptables -A INPUT -p tcp --dport 61616 -s <CONTROLLER_SUBNET> -j ACCEPT"
echo " iptables -A INPUT -p tcp --dport 61616 -j DROP"
Remediation
1. Patch immediately. Upgrade to Armatura One 4.7.2 or later (international) or Armatura One (USA) 4.6.1 or later. Obtain the update only through Armatura's official support channel and verify the package hash against vendor-published values. The official advisory and vendor guidance are linked from CISA ICSA-26-274-01.
2. If you cannot patch this week, isolate. These are the compensating controls that actually reduce risk, in priority order:
- Network isolation: Place Armatura One management servers and controllers on a dedicated, firewalled VLAN. Deny all inbound traffic except from explicitly allowlisted operator workstations and controller IPs. These systems have no business being reachable from user subnets, guest networks, or the internet.
- Block TCP/61616 at the perimeter and internal segmentation boundaries unless Armatura confirms your deployment requires broker access — then restrict by source IP to known controllers only. This directly neutralizes the CVE-2023-46604 vector.
- Audit external exposure NOW: Query Shodan/Censys for your ASN and the Armatura management interface and port 61616. Anything internet-facing is an emergency change, not a change ticket.
3. Rotate everything, then assume rotation is incomplete. Change all customer-configurable credentials on the platform, the underlying database, and any service accounts used by the application. Critically: the hard-coded credentials (CVE-2026-94592) and cryptographic key (CVE-2026-94591) cannot be rotated by you — only the vendor patch removes them. Until patched, your only real mitigation is network-layer access control. Be honest with leadership about that residual risk.
4. Purge and protect the logs (CVE-2026-94593). Identify Armatura application logs containing sensitive material, restrict read access to the application service account only, scrub or securely delete historical log files and any copies that flowed into SIEM/backup pipelines, and hunt for anyone who read those files before you locked them down (the third Sigma rule above).
5. Hunt backward. Patch-then-forget is how organizations get breached twice. Review 30–90 days of telemetry for: child processes of the Java/ActiveMQ service, unexpected inbound connections to 61616, and new local accounts or scheduled tasks on the management host. If the host was internet-reachable at any point, treat it as potentially compromised and consider full DFIR triage before returning it to service.
6. Verify physical integrity. Because the impact here is physical, reconcile door controller configurations, badge access rights, and access-control audit logs against your physical security team's records. Look for doors added to schedules, credentials with unusual privilege, or gaps in badge logs.
Bottom Line
A CVSS 9.8 against a physical access-control system with hard-coded credentials, hard-coded keys, and a publicly weaponized deserialization bug is about as close to "drop everything" as ICS advisories get. The physical-security team and the SOC need to be in the same room for this one — the blast radius is measured in unlocked doors, not just compromised hosts. Patch to 4.7.2 / 4.6.1, isolate the segment, block 61616, and hunt backward before you declare victory.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.