Which Armatura One versions are affected by the CISA advisory?

CISA’s October 01, 2026 ICS advisory names two affected Armatura One version ranges.
Affected versions
According to the advisory context, the affected products are:
| Product | Affected versions |
|---|---|
| Armatura One | Versions earlier than 4.7.2 |
| Armatura One (USA) | Versions earlier than 4.6.1 |
If you operate either product, the key question is whether your deployment is below those version numbers.
Why the advisory matters
CISA says exploitation could allow unauthorized database access, code execution on the host at the highest privilege level, or control of the physical access-control system.
The listed issues include CVE-2023-46604 and CVE-2026-94591 through CVE-2026-94594.
Check the current advisory before acting
ICS advisories can be updated. Operators should review the current CISA advisory and vendor guidance before making upgrade or mitigation decisions.
What should Armatura One operators do after the October 01, 2026 CISA advisory?

Armatura One operators should first confirm whether they are running an affected version, then review CISA’s advisory and any current vendor instructions.
Start with version checking
The advisory identifies these affected products:
- Armatura One versions earlier than 4.7.2
- Armatura One (USA) versions earlier than 4.6.1
That version check is the practical starting point because the advisory applies to specific product ranges.
Why operators should treat it seriously
CISA says exploitation could let an attacker:
- Access the database without authorization
- Run code on the host at the highest privilege level
- Control the physical access-control system
CISA also associates the product with communications, critical manufacturing, energy, and transportation systems sectors, and says deployments are worldwide.
What not to assume
The context does not include a full mitigation checklist, patch instructions, or vendor-specific deployment steps. Operators should not rely on guesses for an access-control system. Use the current CISA advisory and official vendor guidance before making changes.
What could an attacker do by exploiting the Armatura One vulnerabilities?

CISA says exploiting the Armatura One vulnerabilities could affect both software systems and physical access control.
What an attacker could do
The advisory context says exploitation could allow an attacker to:
- Access the database without authorization
- Run code on the host at the highest privilege level
- Control the physical access-control system
Those impacts are why the advisory is especially relevant to organizations using Armatura One in operational environments.
Which CVEs are listed
The issues named in the context include:
- CVE-2023-46604
- CVE-2026-94591
- CVE-2026-94592
- CVE-2026-94593
- CVE-2026-94594
Where the product is used
CISA associates Armatura One with communications, critical manufacturing, energy, and transportation systems sectors. It also says deployments are worldwide.
Because advisory details may change, use the latest CISA page as the reference point for current impact and response information.
Sources / Learn more
Related reading
- How do I update a Eufy Omni C20 or Omni X10 Pro to firmware version 1.6.4 or later?; Which Eufy Omni C20 and Omni X10 Pro firmware versions are affected by the September 24, 2026 CISA advisory?; What should I do if my Eufy Omni C20 or Omni X10 Pro was paired while running firmware before 1.6.4?; What changed in the CISA advisory for Eufy Omni C20 and Omni X10 Pro released on September 24, 2026?
- How can teams determine whether their SIMOVE Fleetmanager or SIPLANT version is affected by CVE-2026-67367?; What should Siemens SIMOVE Fleetmanager and SIPLANT users do after the September 22, 2026 CISA advisory?; What could the path traversal vulnerability allow an attacker to access?; Which SIMOVE Fleetmanager versions are listed as affected before the fixed releases?
- How should Siemens Siveillance Control and Siveillance Control Pro users address CVE-2026-50093?; Which Siveillance Control and Siveillance Control Pro versions are affected by CVE-2026-50093?; How could the Open Interface Services web module vulnerability lead to root-level access?; What changed in the September 22, 2026 CISA advisory for Siemens Siveillance Control?
- How do I check whether my Siemens Industrial Edge Management deployment is in one of the affected version ranges?; What should administrators do after CISA advisory ICSA-26-265-06 for CVE-2026-18963?; What changed in the Siemens update for the reset-credentials vulnerability?; What is the timeline for the Siemens Industrial Edge Management CISA advisory and fix?
![[Armatura LLC Armatura One]: CISA’s Armatura One Advisory: Affected Versions and Exploitation Impact](https://trendingissue.blog/wp-content/uploads/2026/10/pexels-10514729.jpg)