logo

CISA tells feds to patch 13-year-old Apache ActiveMQ bug under active attack

ID: 9e7e1199-a209-50dd-9d8d-fe9d6b8a5c82

STIX ID: report--9e7e1199-a209-50dd-9d8d-fe9d6b8a5c82

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2026-04-17

Date Updated: 2026-04-26

Author: Carly Page

...
...

CISA added CVE-2026-34197 — a 13-year-old remote code execution flaw in Apache ActiveMQ's Jolokia API — to its Known Exploited Vulnerabilities list, urging agencies to patch within two weeks; the issue allows authenticated command execution and can be effectively unauthenticated on certain versions via CVE-2024-32114, with many publicly reachable ActiveMQ instances and available patches in 5.19.5 and 6.2.3.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.