- CISA's October 1, 2026 advisory lists five vulnerabilities in Armatura One, including CVE-2023-46604 in a bundled Apache ActiveMQ, which CISA lists as known exploited.
- CISA is not aware of exploitation aimed at Armatura One. The flaws could still allow code execution on the host and, per CISA, control of the physical access-control system.
- Upgrade to V4.7.2 (or V4.6.1_USA), limit network exposure, review credentials, and ask vendors to list embedded components.
The risk you did not buy
Buyers test the product they purchase. They rarely test the parts inside it. Those parts have their own histories. Some carry known flaws.
A CISA advisory from October 1, 2026 shows the gap. It covers Armatura One, made by the US-based Armatura LLC. CISA says an attacker could reach the database. They could also run code on the host at the top privilege level, or take over the physical access-control system.
The lesson here is that the patch list you keep is not the full list of software you run. Some of it arrives bundled under another name.
What CISA reported
The advisory lists five vulnerabilities. Armatura One V4.7.2 fixes all five. In the USA release line, the fix is V4.6.1_USA.
Affected users run V4.7.1 or earlier. In the USA line, that means V4.3.1_USA or earlier. Armatura advises contacting its official technical support to get and apply the upgrade.
Andrew Capobianco of RewCon.co reported the flaws to CISA. The advisory lists Communications, Critical Manufacturing, Energy and Transportation Systems as sectors involved.
CISA also states a limit. It is not aware of exploitation aimed at Armatura One through these flaws.
How the main flaw works
Armatura One bundles Apache ActiveMQ, a message broker. A broker passes messages between parts of a system. Out of the box, the product leaves the broker's OpenWire listener open on the network. That listener is the broker's network door.
The bundled broker carries CVE-2023-46604. It is a deserialization flaw. Deserialization means rebuilding a software object from incoming data. Here, the rebuild happens before the system checks who sent the data.
Picture a mailroom that opens every package before checking the sender's ID. An attacker on the network needs no login. A crafted package can make the host run the attacker's code. That code then runs with the host's highest level of control.
CISA lists CVE-2023-46604 in its Known Exploited Vulnerabilities catalog. It also ties the flaw to ransomware campaigns against other ActiveMQ deployments. Those are other deployments, not Armatura One. The advisory gives no dates for the listing or the campaigns.
Four problems with secrets
The other four issues involve credentials, meaning passwords and keys. They matter more together than apart.
First, the install configuration file holds the database and broker logins. When protection is on, they are encrypted with AES-128-CBC. But the key, and its companion value called the initialization vector, are fixed inside the software. Every installation shares them.
Anyone with the installation package can extract that key. With a copy of one site's configuration file, they can then read that site's logins.
Second, the database superuser account is created with a password chosen by the vendor. It is not unique to each site. If nobody changed it, a person with access to the server's operating system and that password can sign in as superuser.
Third, the backup and restore routine leaves a record on the host. The record holds the full database connection command as readable text. The superuser password is in it.
Fourth, the message broker writes client logins and passwords to its log in readable text during normal use. Anyone who can read that log can take them. The same goes for a backup or support bundle that includes the log.
Most of these need some access first, such as to the server or a file. That limits who can use them. It also means a small foothold elsewhere could be worth more than it looks.
The component nobody on the buying team sees
This software decides who enters a building. The facilities manager or security lead may never see the word ActiveMQ.
The advisory is a plain supply-chain reminder. A flaw with a 2023 CVE number, which CISA lists as known exploited, still sits inside a product advisory in late 2026. This is one advisory about one product. It does not show how common the problem is. It does show which question to ask.
What to ask your team
Ask whether Armatura One is deployed, and which version. If it is, find out whether the upgrade is scheduled with the vendor's support team.
Ask whether the broker's network listener can be reached from outside its own segment. CISA advises keeping control systems off the internet. It also advises placing them behind firewalls, away from business networks.
Where remote access is needed, CISA points to VPNs. It adds that VPNs can have flaws and need updates.
Ask whether credentials need rotating after the upgrade. Logged and fixed passwords may have been read before the fix. The advisory does not say whether that happened. Your team has to check locally.
Finally, ask every security vendor for a list of embedded components. Software you cannot list is software you cannot patch.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: CISA.





