Hitachi Energy's SOI grid monitoring platform has a hole that lets a logged-in attacker take over the server outright.
CISA and Hitachi Energy disclosed CVE-2026-34197, a code injection flaw in the Apache ActiveMQ message broker bundled with SOI versions 2.0.0 through 2.2.0. The bug lives in ActiveMQ's Jolokia JMX-HTTP bridge, which by default lets anyone exec operations on broker objects. An authenticated attacker can send a crafted discovery URI that makes the broker load a remote Spring XML configuration, and because Spring instantiates beans before ActiveMQ validates anything, that config can call Runtime.exec() and run arbitrary code on the broker's JVM. The flaw scores 8.8 out of 10 on the CVSS scale. Hitachi Energy's fix, patch SOI EP2, upgrades the bundled ActiveMQ to version 5.19.5 and installs a newer OpenJDK 11 runtime.
SOI runs on energy infrastructure worldwide, and this isn't a hypothetical misconfiguration - it's the default behavior of a core open-source component vendors keep bundling without hardening. Needing authentication first blunts the blast radius, but once an attacker has any valid session, they get full code execution on equipment tied to the power grid. It's a reminder that ICS vendors inherit every flaw baked into their open-source dependencies, audited or not.
CISA's boilerplate advice - isolate the network, use a VPN - is the same checklist it hands out for nearly every ICS bug; the actual fix here is EP2, not another firewall rule.