Critical Remote Code Execution Vulnerability in Hitachi Energy SOI
CVE-2026-34197 affects Apache ActiveMQ component, CVSS 8.8
Key Takeaways
- CVE-2026-34197 is a Remote Code Execution vulnerability in Hitachi Energy SOI's Apache ActiveMQ component, CVSS 8.8.
- Affected versions: SOI 2.0.0 through 2.2.0.
- The flaw exploits the Jolokia JMX-HTTP bridge's default access policy to execute arbitrary code on the broker's JVM.
- Hitachi Energy has released cumulative patch SOI EP2 upgrading ActiveMQ to version 5.19.5.
- The vulnerability impacts Critical Infrastructure Energy sector with worldwide deployment.
Quick answers
Related Security News
Six Vulnerabilities Discovered in Hitachi Energy RTU500 End-of-Life Firmware
Hitachi Energy has published a cybersecurity advisory addressing six vulnerabilities in its RTU500 series CMU firmware versions 11.x and prior, identified by Dragos and tracked by CISA. The flaws range from authentication bypass and relative path traversal to improper authorization, with CVSS scores of 9.1. End-of-life versions are no longer maintained, and Hitachi Energy recommends upgrading to currently supported firmware versions 12.7.8 or 13.9.1 or later.




