Claude Finds 13-Year-Old 0-Day RCE Vulnerability in Apache ActiveMQ in 10 Minutes
ID: 972b4350-4ef2-5d2d-92d3-960ba88f7a80
STIX ID: report--972b4350-4ef2-5d2d-92d3-960ba88f7a80
Feed Name: cybersecurityNews.com
**Apache ActiveMQ RCE (CVE-2026-34197):** A critical remote code-execution flaw in ActiveMQ Classic's Jolokia JMX-HTTP bridge allows an attacker to use addNetworkConnector with a crafted vm:// xbean URL that causes Spring to instantiate remote beans and execute arbitrary OS commands; versions 6.0.0–6.1.1 are unauthenticated due to CVE-2024-32114, patches are available in 5.19.4 and 6.2.3, and organizations should update immediately, audit for default credentials, and monitor Jolokia API calls, vm:// URIs with brokerConfig=xbean:http, outbound HTTP from the ActiveMQ process, and unexpected child processes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
