CISA tells feds to patch 13-year-old Apache ActiveMQ bug under active attack
ID: 9e7e1199-a209-50dd-9d8d-fe9d6b8a5c82
STIX ID: report--9e7e1199-a209-50dd-9d8d-fe9d6b8a5c82
Feed Name: The Register (Security)
Threat Score
CISA added CVE-2026-34197 — a 13-year-old remote code execution flaw in Apache ActiveMQ's Jolokia API — to its Known Exploited Vulnerabilities list, urging agencies to patch within two weeks; the issue allows authenticated command execution and can be effectively unauthenticated on certain versions via CVE-2024-32114, with many publicly reachable ActiveMQ instances and available patches in 5.19.5 and 6.2.3.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
