As reported by CISA in advisory ICSA-26-274-01, Armatura LLC has disclosed a critical-severity vulnerability cluster affecting its Armatura One physical access-control platform. With a CVSS v3 score of 9.8, the advisory details five CVEs — CVE-2023-46604, CVE-2026-94591, CVE-2026-94592, CVE-2026-94593, and CVE-2026-94594 — impacting Armatura One versions prior to 4.7.2 and Armatura One (USA) versions prior to 4.6.1. Patches are available: V4.7.2 for the standard line and V4.6.1_USA for the USA release.
Why This Matters: The Physical-Cyber Convergence
Physical access-control systems sit at a dangerous intersection that many cybersecurity programs under-prioritize. These aren't just databases — they govern badge readers, door controllers, and entry logging for facilities. When an attacker achieves code execution on the host operating system with the highest level of privilege, as CISA warns is possible here, they aren't just stealing data. They can manipulate who gets through which doors, erase audit trails of their physical presence, or lock out legitimate personnel during an incident.
The advisory explicitly names Communications, Critical Manufacturing, Energy, and Transportation Systems as affected critical infrastructure sectors — industries where unauthorized physical access to a substation, manufacturing floor, or communications hub can be catastrophic.
The Embedded Component Problem
The presence of CVE-2023-46604 — a well-known Apache ActiveMQ deserialization flaw publicly disclosed in 2023 and added to CISA's Known Exploited Vulnerabilities catalog — inside a product advisory dated October 2026 highlights a persistent supply chain challenge: embedded components age silently while the products wrapping them continue shipping.
Apache ActiveMQ's OpenWire protocol listener is exposed on the network by default in the embedded Armatura deployment. An unauthenticated attacker can trigger deserialization of an arbitrary object graph before authentication is even checked, achieving arbitrary code execution at the host's highest privilege level. This is the kind of vulnerability that ransomware operators and initial access brokers actively scan for.
Additional Vulnerability Classes
Who Is Most Exposed
Organizations running Armatura One deployments that are internet-facing or reside on flat network segments without segmentation from corporate IT are at highest risk. Facilities in the named critical infrastructure sectors — particularly energy substations and transportation hubs where physical access systems may be managed by OT teams with limited cybersecurity oversight — face compounded exposure. The product is deployed worldwide, broadening the potential attack surface.
Shield53 Recommendations
Immediate Actions
- Patch immediately: Upgrade to Armatura One V4.7.2 (or V4.6.1_USA for the USA release line). Contact Armatura technical support if upgrade packages are not directly accessible.
- Network segmentation: Ensure the ActiveMQ OpenWire listener (TCP port 61616 by default) is never exposed to untrusted networks. Place access-control infrastructure on isolated VLANs with strict firewall rules limiting access to management workstations only.
- Detect active exploitation: Monitor for anomalous connections to the ActiveMQ port, unexpected Java process execution on the Armatura host, and unusual outbound network connections indicating post-exploitation C2 activity.
- Audit access logs: Review historical badge access events for anomalies — unauthorized door unlocks, credential creations, or modified access groups — that may indicate prior compromise.
- Inventory embedded components: Conduct a software bill of materials (SBOM) review across all physical security systems to identify other silently-embedded, end-of-life, or known-vulnerable components.
Broader Guidance
Physical security teams and cybersecurity teams must break down silos. Access-control platforms are IT assets with physical consequences and should be governed under the same vulnerability management, asset inventory, and threat monitoring programs as critical business systems. CISA's advisory is a reminder that the boundary between cyber and physical is artificial — attackers don't respect it, and defenders shouldn't either.