Armatura One access control ships an exploited ActiveMQ bug
CISA warns Armatura One embeds an ActiveMQ flaw used in ransomware attacks, plus fixed keys and passwords. Versions, checks and cleanup steps.
By Yaali. October 2, 2026, 6 min read, Vulnerabilities, Patching, Resilience.
Armatura One, a web-based security platform that runs door access control, elevator control, visitor management and video for a building, has five vulnerabilities in a CISA advisory published on October 1, 2026 (ICSA-26-274-01). The worst is not new: the product embeds Apache ActiveMQ, a Java message broker, with a version still open to CVE-2023-46604, a CVSS 9.8 remote code execution flaw that has been in CISA's Known Exploited Vulnerabilities (KEV) catalog since November 2, 2023. The other four are hard-coded keys, a fixed database password and passwords written to log files.
Affected are Armatura One before 4.7.2 and the US release line before 4.6.1_USA. CISA lists Communications, Critical Manufacturing, Energy and Transportation Systems among the sectors using it, worldwide. Its summary is blunt: exploitation could give an attacker the database, code execution on the host "with the highest level of privilege", or control of the physical access-control system. If this server decides which badges open which doors in your buildings, upgrade it this week.

How it works
Armatura One is a server and browser application: the server holds the database of people, cards and access rules, and staff manage it from a web console. Inside, CISA says, it embeds ActiveMQ with the OpenWire protocol listener exposed on the network by default. OpenWire is ActiveMQ's native wire format, and on a standard ActiveMQ install it listens on TCP 61616.
CVE-2023-46604 is a flaw in how the Java OpenWire marshaller handles serialized objects. A client can name a class type in a message, and the broker instantiates it before any authentication check happens. In the attacks investigated in 2023, this made the broker fetch an XML configuration file from a server the attacker controlled, and the broker process then ran the attacker's shell commands. No account is needed, only a network path to the listener. Apache fixed it in ActiveMQ 5.15.16, 5.16.7, 5.17.6 and 5.18.3 in October 2023, but an application that bundles its own older copy stays vulnerable until the vendor ships a new build, which is what happened here.
The other four CVEs turn a foothold into the keys to the whole system:
- CVE-2026-94591 (CVSS 8.4): the database and broker credentials in the install configuration file are encrypted with AES-128-CBC, but the key and initialization vector are fixed values inside the software, identical on every installation. Anyone with the installer can recover them and decrypt the config file from any site.
- CVE-2026-94592 (CVSS 8.4): the database setup gives the superuser account a vendor-defined password instead of a unique one, so a deployment where nobody changed it accepts that password.
- CVE-2026-94593 (CVSS 7.8): backup and restore routines write the full database connection command, superuser password included, to plain-text log files.
- CVE-2026-94594 (CVSS 4.0): the message broker logs client connection credentials in plain text during normal operation, which puts them in log copies, backups and support bundles.
Chained, the flaws mean that anyone who gets onto the server, through the broker or any other way, can recover the database superuser password from the config file, the default value or the logs. CISA's advisory names unauthorized database access and control of the physical access-control system as the outcomes.
What attackers are doing
CISA says no exploitation aimed at Armatura One itself is known. CVE-2023-46604 has a long record elsewhere, though, and CISA's advisory notes it has been used in ransomware campaigns against other ActiveMQ deployments. Rapid7 saw attackers exploit it to deploy HelloKitty ransomware starting October 27, 2023. Arctic Wolf documented a separate campaign that used the same flaw to deliver TellYouThePass ransomware.
CISA rates exploitation as needing no authentication and no user interaction for CVE-2023-46604. The flaws were reported to CISA by Andrew Capobianco of RewCon.co.
What to do

1. Upgrade
Move to Armatura One 4.7.2, or 4.6.1_USA on the US release line. Armatura LLC asks customers to contact its technical support for the upgrade package and guidance on applying it, so open that ticket today rather than waiting for a maintenance window.
2. If you cannot upgrade yet
Find the broker port first. CISA does not say which port Armatura One uses for OpenWire, so on the server run netstat -ano | findstr LISTENING, match the process IDs to the Java processes in Task Manager, and look for 61616 or another port the broker owns. Then allow that port only from the door controllers and workstations that need it, on the Windows firewall and on the network firewall in front of the server. CISA's general advice for control systems applies too: no internet exposure, the server behind a firewall and separate from the business network, and VPN for any remote access.
This narrows who can reach the listener. It does not remove the flaw, and a compromised workstation on an allowed segment can still exploit it.
3. Check whether you were hit
Published investigations of CVE-2023-46604 attacks show a consistent process chain on Windows: java.exe makes an HTTP request to download an XML file, then starts cmd.exe, which launches msiexec.exe to pull a payload (Rapid7 saw one disguised as a .png file) or PowerShell to fetch more tools. In your endpoint detection tool, or in Sysmon event ID 1 (process creation), search for cmd.exe, msiexec.exe or powershell.exe with a java.exe parent on the Armatura One server. Also check firewall logs for outbound HTTP from that server to addresses that are not your update sources.
In the database, compare the enrolled personnel, cards and access levels with HR and facilities records, and look for new administrator accounts in the Armatura One console.
4. Clean up
After the upgrade, change the database superuser password and the broker credentials, because the old ones may have been readable from the fixed key, the default value or the logs. Find the backup and restore logs and the broker logs on the server, in backup sets and in any support bundle you have sent out, and delete or restrict them, since each copy contains working passwords until those are changed.
The wider lesson
Physical security servers tend to belong to facilities teams and integrators, so they miss the vulnerability scans and patch cycles the IT estate gets. This advisory shows the cost: an ActiveMQ flaw patched upstream in October 2023 was still inside every Armatura One release before 4.7.2, three years later. Add these servers to your asset inventory and to software composition checks, and ask vendors which third-party components they bundle.
Our network penetration tests look at which building and OT management servers can be reached from user networks, and our safeguarding and hardening work closes those paths. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.
Sources: CISA ICSA-26-274-01, Assurant Cyber summary of ICSA-26-274-01, Apache ActiveMQ CVE-2023-46604 announcement, Rapid7, Arctic Wolf, Security Affairs, ZKTeco USA, Armatura One, Armatura One product page.
Read next
- Veeam Agent flaw lets local users become SYSTEM
- AI agent chains two Zammad zero-days to root at DIVD
- FortiMail zero-day: disable IBE now, fixes still pending
Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.