Armatura One access-control system has critical flaws
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
Armatura One physical access-control software bundles a vulnerable Apache ActiveMQ and hard-coded credentials, risking full system compromise; patch to 4.7.2/4.6.1.
CISA has published an ICS advisory for Armatura LLC's Armatura One physical access-control platform, detailing five vulnerabilities affecting versions prior to 4.7.2 (and 4.6.1 for the USA release line). The most severe, CVE-2023-46604, stems from an embedded, network-exposed Apache ActiveMQ instance vulnerable to a well-known OpenWire deserialization flaw that allows unauthenticated remote code execution with the highest host privileges. This CVE is already listed in CISA's KEV catalog and has been used in ransomware campaigns against other ActiveMQ deployments, though CISA states it is not aware of exploitation specifically targeting Armatura One.
The remaining four vulnerabilities compound the risk: a hard-coded AES-128-CBC key/IV used across all installations (CVE-2026-94591) lets an attacker with the installer decrypt stored database/broker credentials; a fixed, vendor-defined database superuser password set at install time (CVE-2026-94592) permits local authentication if unchanged; plaintext logging of database superuser credentials during backup/restore (CVE-2026-94593); and plaintext logging of message-broker client credentials during normal operation (CVE-2026-94594). Together these could let an attacker move from network access to full database and physical access-control system compromise.
Affected deployments span Communications, Critical Manufacturing, Energy, and Transportation Systems sectors worldwide, with the vendor headquartered in the US. Armatura has released fixed versions 4.7.2 (general) and 4.6.1_USA (USA line); defenders should upgrade immediately, rotate any potentially exposed database/broker credentials, isolate control system networks from the internet and business networks, and use VPNs for remote access. The vulnerabilities were reported to CISA by Andrew Capobianco of RewCon.co.
Mentioned in this report
Detection guidance
ActiveMQ Java Process Spawning Shell or Download Utility (Windows)
Detects a Java process running Apache ActiveMQ spawning a shell, scripting host or download utility, consistent with CVE-2023-46604 OpenWire deserialization RCE on embedded brokers such as Armatura One. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.
title: ActiveMQ Java Process Spawning Shell or Download Utility (Windows)
id: 408ca016-62c2-508d-9478-9d5b9ff0e73e
status: experimental
description: Detects a Java process hosting Apache ActiveMQ spawning cmd, PowerShell,
script hosts or LOLBin download utilities. This is the typical post-exploitation
pattern of CVE-2023-46604 (OpenWire deserialization RCE) against embedded ActiveMQ
brokers such as the one in Armatura One. Matches on the parent/child relation, not
on payload names.
tags:
- attack.initial-access
- attack.t1190
- attack.execution
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- \java.exe
- \javaw.exe
ParentCommandLine|contains: activemq
selection_child:
Image|endswith:
- \cmd.exe
- \powershell.exe
- \pwsh.exe
- \wscript.exe
- \cscript.exe
- \mshta.exe
- \certutil.exe
- \bitsadmin.exe
- \curl.exe
- \rundll32.exe
- \regsvr32.exe
- \msiexec.exe
condition: selection_parent and selection_child
falsepositives:
- Administrator-written ActiveMQ wrapper or maintenance scripts launched via cmd from
the broker service
- Service installers or upgrade routines that invoke cmd.exe from the ActiveMQ Java
process
level: high
author: Vorant
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01
ActiveMQ Java Process Spawning Shell or Download Utility (Linux)
Detects a Java process running Apache ActiveMQ spawning a shell, downloader or netcat on Linux, consistent with CVE-2023-46604 exploitation. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.
title: ActiveMQ Java Process Spawning Shell or Download Utility (Linux)
id: a65e1291-8f6f-531c-b513-d3173cb5dc02
status: experimental
description: Detects the Java process hosting Apache ActiveMQ spawning a shell, curl,
wget, netcat or scripting interpreter on Linux. This is the typical post-exploitation
pattern of CVE-2023-46604 (OpenWire deserialization RCE) against exposed brokers.
tags:
- attack.initial-access
- attack.t1190
- attack.execution
logsource:
category: process_creation
product: linux
detection:
selection_parent:
ParentImage|endswith: /java
ParentCommandLine|contains: activemq
selection_child:
Image|endswith:
- /sh
- /bash
- /dash
- /curl
- /wget
- /nc
- /ncat
- /python
- /python3
- /perl
condition: selection_parent and selection_child
falsepositives:
- ActiveMQ startup or wrapper scripts that call sh or bash from the broker JVM
- Custom broker health-check scripts invoked by the Java process
level: high
author: Vorant
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01
Recursive Search of Log Files for Plaintext Passwords
Detects findstr or Select-String being used to search log files for password strings, which would expose the plaintext credentials logged by the Armatura One backup/restore and broker flaws. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.
title: Recursive Search of Log Files for Plaintext Passwords
id: 4569ad63-ab25-53be-8a7f-69e689d96cc6
status: experimental
description: Detects findstr or Select-String being used to search log files for password
strings. Applications that log database superuser or message-broker credentials
in plaintext (as described for Armatura One CVE-2026-94593 and CVE-2026-94594) expose
them to this kind of credential harvesting. Tune by excluding known admin troubleshooting
accounts.
tags:
- attack.credential-access
- attack.t1552.001
logsource:
category: process_creation
product: windows
detection:
selection_findstr:
Image|endswith: \findstr.exe
CommandLine|contains|all:
- /s
- password
- .log
selection_pwsh:
Image|endswith:
- \powershell.exe
- \pwsh.exe
CommandLine|contains|all:
- Select-String
- password
- .log
condition: 1 of selection_*
falsepositives:
- Administrators troubleshooting application logs for authentication errors
- Security audit or secret-scanning scripts run by IT staff
level: medium
author: Vorant
references:
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01
Behavioural rules are generated from public reporting — validate in your environment before deploying.
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 10,566 reports from 152 sources, 502 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs