CISA warns Armatura One embeds an Apache ActiveMQ still open to the 2023 flaw CVE-2023-46604, letting any network attacker run code at top privilege. Upgrading to 4.7.2, or 4.6.1 for the US build, closes it alongside four CVEs assigned in 2026.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence70
CISA says Toptech TMS7 and TopHAT 7.6.3 carry ten CVEs, one of which lets unauthenticated attackers export any database table they choose. Toptech told customers on July 20 that release 7.8 fixes them, so the sites at risk are those still on 7.6.3.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap0
- Incentives
- Insufficient
- Confidence68
CISA's advisory for the Android and iOS app describes read access to real-time data for every active device on a shared broker. The fix is an app store update, and a credential already extracted still works until Bransys changes it.
Reality
- Evidence68
- Adoption25
- Hype gap0
- Incentives30
- Confidence70
CISA's advisory covers four CVEs in AVEVA Pipeline Integrity Monitor builds up to 2025 SP1 P1. The fix reaches only the project files you can migrate, and the migration to SP1 P2 cannot be undone.
Reality
- Evidence62
- Adoption18
- Hype gap+5
- Incentives55
- Confidence58
CVE-2026-59086 yields code execution in Simcenter Femap and Nastran below V2606. The fix already exists; the engineering workstations that need it rarely sit inside the monthly cycle.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence62