[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"branding":3,"analytics":7,"article-hitachi-energy-patches-code-execution-bug-in-grid-monitoring-tool":10,"sections":35},{"siteName":4,"siteTagline":5,"publisherName":4,"contactEmail":6},"The Revision","Tech news, decoded.","editor@therevision.news",{"gaMeasurementId":8,"adsenseClientId":9},"G-ZW2MV82GYR","ca-pub-8533917693782264",{"article":11},{"id":12,"slug":13,"title":14,"dek":15,"body_md":16,"tags_json":17,"published_at":18,"created_at":19,"updated_at":20,"status":21,"review_note":22,"review_notes":23,"image_url":22,"persona_id":22,"persona_name":22,"section":24,"tags":25,"sources":30,"feedback":34,"feedback_at":22,"cost_usd":34,"total_tokens":34},10380,"hitachi-energy-patches-code-execution-bug-in-grid-monitoring-tool","Hitachi Energy Patches Code Execution Bug in Grid Monitoring Tool","A critical Apache ActiveMQ flaw in Hitachi Energy's SOI grid software lets authenticated attackers run code remotely, and a patch is now out.","Hitachi Energy's SOI grid monitoring platform has a hole that lets a logged-in attacker take over the server outright.\n\nCISA and Hitachi Energy disclosed CVE-2026-34197, a code injection flaw in the Apache ActiveMQ message broker bundled with SOI versions 2.0.0 through 2.2.0. The bug lives in ActiveMQ's Jolokia JMX-HTTP bridge, which by default lets anyone exec operations on broker objects. An authenticated attacker can send a crafted discovery URI that makes the broker load a remote Spring XML configuration, and because Spring instantiates beans before ActiveMQ validates anything, that config can call Runtime.exec() and run arbitrary code on the broker's JVM. The flaw scores 8.8 out of 10 on the CVSS scale. Hitachi Energy's fix, patch SOI EP2, upgrades the bundled ActiveMQ to version 5.19.5 and installs a newer OpenJDK 11 runtime.\n\nSOI runs on energy infrastructure worldwide, and this isn't a hypothetical misconfiguration - it's the default behavior of a core open-source component vendors keep bundling without hardening. Needing authentication first blunts the blast radius, but once an attacker has any valid session, they get full code execution on equipment tied to the power grid. It's a reminder that ICS vendors inherit every flaw baked into their open-source dependencies, audited or not.\n\nCISA's boilerplate advice - isolate the network, use a VPN - is the same checklist it hands out for nearly every ICS bug; the actual fix here is EP2, not another firewall rule.","[\"ics security\",\"apache activemq\",\"hitachi energy\",\"cve-2026-34197\"]","2026-10-06T12:00:00.000Z","2026-10-07T01:14:40.247Z","2026-10-07T01:14:45.631Z","published",null,[],"security",[26,27,28,29],"ics security","apache activemq","hitachi energy","cve-2026-34197",[31],{"name":32,"url":33},"CISA Advisories","https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fics-advisories\u002Ficsa-26-279-04",0,{"sections":36},[37,42,46,51,56,61,66,71,76,81,86,91,95,100],{"name":38,"slug":39,"count":40,"latest_published_at":41},"AI","ai",6357,"2026-10-06T17:28:33.000Z",{"name":43,"slug":24,"count":44,"latest_published_at":45},"Security",892,"2026-10-06T17:50:11.000Z",{"name":47,"slug":48,"count":49,"latest_published_at":50},"Policy","policy",468,"2026-10-06T17:01:52.000Z",{"name":52,"slug":53,"count":54,"latest_published_at":55},"Deals","deals",406,"2026-10-06T18:26:53.000Z",{"name":57,"slug":58,"count":59,"latest_published_at":60},"Hardware","hardware",216,"2026-10-06T18:22:57.000Z",{"name":62,"slug":63,"count":64,"latest_published_at":65},"Science","science",184,"2026-10-06T18:10:45.000Z",{"name":67,"slug":68,"count":69,"latest_published_at":70},"Consumer Tech","consumer-tech",165,"2026-10-06T17:31:59.000Z",{"name":72,"slug":73,"count":74,"latest_published_at":75},"Software","software",109,"2026-10-06T17:06:24.000Z",{"name":77,"slug":78,"count":79,"latest_published_at":80},"Startups","startups",105,"2026-10-06T16:29:12.000Z",{"name":82,"slug":83,"count":84,"latest_published_at":85},"Dev Tools","dev-tools",103,"2026-10-06T17:20:00.000Z",{"name":87,"slug":88,"count":89,"latest_published_at":90},"Gaming","gaming",55,"2026-10-06T09:38:03.000Z",{"name":92,"slug":93,"count":89,"latest_published_at":94},"General","general","2026-10-06T13:57:32.000Z",{"name":96,"slug":97,"count":98,"latest_published_at":99},"Reviews","reviews",33,"2026-10-05T11:57:17.000Z",{"name":101,"slug":102,"count":103,"latest_published_at":104},"How-To","how-to",8,"2026-10-05T09:00:00.000Z"]