Hitachi Energy SOI

Summary

Hitachi Energy has identified a critical Remote Code Execution (RCE) vulnerability, CVE-2026-34197, in the Apache ActiveMQ component used in specific versions of its SOI product (versions 2.0.0 to 2.2.0). Exploiting this flaw could compromise the confidentiality, integrity, and availability of the product.

IFF Assessment

FOE

This vulnerability allows for arbitrary code execution, posing a significant risk to critical infrastructure and data security.

Severity

8.8 High

CISA KEV: Listed as actively exploited. Federal patch due: April 30, 2026. Known ransomware use: Unknown.

Defender Context

This alert highlights a critical vulnerability in the Hitachi Energy SOI product, affecting the energy sector and deployed globally. Defenders should prioritize patching or applying mitigations to affected systems immediately, as this vulnerability allows for remote code execution.

Read Full Story →