Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Remote Code Execution & Privilege‑Escalation Vulnerabilities in Armatura One Access‑Control System (CVE‑2023‑46604, CVE‑2026‑94591‑94594)

Armatura One controllers contain five critical flaws that allow unauthenticated attackers to execute code with system privileges and manipulate physical access controls. The issue underscores the need for continuous vendor risk monitoring and auditable remediation evidence.

LiveThreat™ Intelligence · 📅 October 01, 2026· 📰 cisa.gov
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
4 recommended
📰
Source
cisa.gov

Critical Remote Code Execution & Privilege‑Escalation Vulnerabilities in Armatura One Access‑Control System (CVE‑2023‑46604, CVE‑2026‑94591‑94594)

What It Is – A set of five high‑severity flaws in Armatura LLC’s Armatura One physical‑access‑control platform, including an unauthenticated deserialization bug in the embedded Apache ActiveMQ listener, hard‑coded cryptographic keys, hard‑coded credentials, and excessive logging of sensitive data.

Exploitability – The OpenWire deserialization issue (CVE‑2023‑46604) can be triggered over the network before authentication, enabling remote code execution with system‑level privileges. CVSS v3 9.8 (critical). Public exploits and proof‑of‑concept code have been observed in the wild.

Affected Products –

  • Armatura One < 4.7.2 (global)
  • Armatura One (USA) < 4.6.1

Why It Matters for Trust & Control Assurance

  • Continuous Vendor Oversight – Demonstrating that you monitor third‑party advisories and apply patches promptly is core evidence for access‑control and supply‑chain controls across frameworks.
  • Defensible Audit Trail – Documenting remediation (patch version, configuration change) provides the audit‑ready artifacts required for control‑objective verification.
  • Risk of Physical‑Security Breach – Compromise of the access‑control system can translate into unauthorized entry to critical‑infrastructure sites, amplifying the need for robust change‑management and logging controls.

Recommended Actions

  • Upgrade all Armatura One installations to ≥ 4.7.2 (or ≥ 4.6.1 for U.S. deployments).
  • Disable the embedded ActiveMQ OpenWire listener if not required, or restrict it to a trusted network segment.
  • Conduct a focused vulnerability scan on all physical‑security controllers and capture remediation evidence for audit purposes.
  • Review logging configurations to ensure no sensitive credentials are written to logs.

Source: CISA Advisory – ICSA‑26‑274‑01

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-274-01 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →