Daily OT security briefing for October 05, 2026.
Critical Armatura One flaws put physical-access control systems at risk
Security Boulevard summarizes CISA advisory ICSA-26-274-01, which identifies five vulnerabilities in Armatura One that can enable unauthorized database access, arbitrary code execution via an unauthenticated Apache ActiveMQ/OpenWire deserialization issue (CVE-2023-46604), or control of the access-control system. CISA names affected versions and recommends updates, reduced network exposure, segmentation, and secure remote access, and notes it is not aware of exploitation specifically targeting Armatura One while the embedded ActiveMQ flaw has been exploited in other deployments.
Source: Security Boulevard — Daily OT Security News.
Monta charging-station platform weaknesses expose EV operations to takeover and disruption
Security Boulevard summarizes CISA advisory ICSA-26-274-02, which reports four flaws affecting all versions of the Monta monta.app EV-charging platform, including an unauthenticated WebSocket endpoint (CVE-2026-95102) that CISA rates CVSS 9.4 and that can enable station impersonation and unauthorized actions. The advisory also covers unrestricted authentication attempts, predictable or reusable session identifiers, and exposed station identifiers; Monta is increasing authenticated connections and adding WebSocket rate limiting and automated throttling, and CISA reports no known public exploitation.
Source: Security Boulevard — Daily OT Security News.
ABB PCM600 advisory flags privilege escalation and archive path-traversal risks in energy environments
Security Boulevard summarizes CISA advisory ICSA-26-274-03, which identifies two vulnerabilities in ABB PCM600 version 2.14 and earlier that can allow local privilege escalation via the PCM600 Scheduler Service (CVE-2026-15952) and path-traversal when extracting project archives (CVE-2026-15953). CISA lists CVSS scores of 6.4 and 5.0, identifies the energy sector as affected, notes no known public exploitation, and documents a vendor workaround to run the scheduler service under the same Windows account used for PCM600.
Source: Security Boulevard — Daily OT Security News.
Johnson Controls EasyIO Neo controller advisories call for immediate firmware and TLS hardening
Security Boulevard reports that CISA advisories ICSA-26-274-04 and ICSA-26-274-05 cover EasyIO Neo EC and CW programmable edge controllers, identifying exposure of sensitive information and cleartext transmission of credentials and session data. CISA recommends upgrading to fixed releases (EC V3.3b64 and CW V3.3b26), enforcing HTTPS/TLS and disabling HTTP by default where available, and using segmentation, VPNs or ACLs; CISA reports no known public exploitation.
Source: Security Boulevard — Daily OT Security News.
Meari IoT Cloud authorization flaws can expose device credentials, telemetry, and control
Security Boulevard summarizes a CISA advisory describing two missing-authorization vulnerabilities in all versions of the Meari IoT Cloud Platform OpenAPI Service that can let authenticated users manipulate devices they do not own (CVE-2026-101104, CVSS 7.7) or retrieve complete device shadows including credentials and telemetry (CVE-2026-96613, CVSS 6.5). CISA reports that Meari did not respond to coordination attempts and that no fix was planned, and recommends reducing internet exposure, network isolation, and secured remote access.
Source: Security Boulevard — Daily OT Security News.
For technical details and mitigation steps, consult the linked Security Boulevard article and the referenced CISA and vendor advisories.