Skip to content

Security1 publisher2 min readPublished

Hitachi Energy SOI versions 2.0.0 to 2.2.0 carry a remote code execution flaw in bundled ActiveMQ

Hitachi Energy says SOI versions 2.0.0 through 2.2.0 carry CVE-2026-34197, a remote code execution flaw in their bundled Apache ActiveMQ component. CISA's scoring as of 28 September records no exploitation, so operators have time to find SOI hosts and fix them on a planned schedule.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Hitachi Energy SOI versions 2.0.0 to 2.2.0 carry a remote code execution flaw in bundled ActiveMQ
Generated illustration

What happened

  • The flaw can be used in attacks on the confidentiality, integrity and availability of SOI, according to Hitachi Energy.
  • CISA lists energy as the affected sector and says SOI, from the Switzerland-headquartered company, is deployed worldwide.
  • Hitachi Energy's internal team reported the vulnerability to CISA, according to the advisory's acknowledgments.
  • The advisory refers operators to Hitachi Energy's Recommended Immediate Actions for mitigation and remediation steps.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Teams that patch Apache ActiveMQ only as a standalone product need to treat SOI 2.0.0 to 2.2.0 hosts as ActiveMQ hosts too.
  • constraint Every interim control in the advisory is network isolation, so SOI hosts reachable from business networks or the internet sit outside the protection the guidance assumes.
  • contradiction Hitachi Energy's summary speaks of vulnerabilities in the plural while listing one CVE, so the scope may extend past CVE-2026-34197 until the vendor clarifies it.

CISA attached the SSVC vector E:N/A:N to the advisory, timestamped 28 September 2026 at 14:31 UTC [6]. Under SSVC v2, E:N means no evidence of active exploitation and no public proof of concept [13]. A:N means an attacker cannot reliably automate the steps leading up to exploitation [13]. For triage, the second value carries more weight. Nobody can script this against every reachable SOI install at once. Each target takes manual work [13].

Operators running SOI 2.0.0 through 2.2.0 carry a known remote code execution flaw inherited from an open-source component [1][2]. On CISA's scoring, nobody is known to be using it [13]. The CISA text does not describe what SOI does on an operator's network, list a fixed release or CVSS score, or tie the flaw to a threat actor or campaign [12].

The defensive guidance is about where the hosts sit on the network. CISA recommends keeping control system devices off the internet, behind firewalls and isolated from business networks, with VPNs for remote access [8]. It adds that a "VPN is only as secure as its connected devices" [8]. Hitachi Energy's own baseline for process control systems calls for physical protection, no direct internet connections and firewall separation with a minimal number of exposed ports [9]. CISA also tells operators to run an impact analysis and risk assessment before deploying any of it [11].

What to watch

  • Hitachi Energy naming a fixed SOI release or upgrade path for CVE-2026-34197 in its Recommended Immediate Actions.
  • Any change in CISA's SSVC exploitation value for CVE-2026-34197 from none to proof of concept or active.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories