Cyber Security· Important
Hitachi Energy SOI Hit by High-Severity ActiveMQ Code Execution Flaw
CISA published an advisory for Hitachi Energy's SOI product, versions 2.0.0 through 2.2.0, affected by CVE-2026-34197, a code-injection vulnerability in the Apache ActiveMQ component with a CVSS score of 8.8. An authenticated attacker can abuse the Jolokia JMX-HTTP bridge exposed by ActiveMQ to trigger remote code execution on the broker's JVM. Hitachi Energy has released the EP2 patch, which upgrades ActiveMQ to version 5.19.5 and updates related OpenJDK and client components.