logo

U.S. CISA adds a flaw in Apache ActiveMQ to its Known Exploited Vulnerabilities catalog

ID: 59da6300-d636-595d-bdba-3b1fc4e780b5

STIX ID: report--59da6300-d636-595d-bdba-3b1fc4e780b5

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-04-17

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CISA has added CVE-2026-34197 — a critical (CVSS 8.8) remote code execution flaw in Apache ActiveMQ’s Jolokia JMX-HTTP bridge — to its Known Exploited Vulnerabilities catalog. Authenticated attackers can craft requests that cause the broker to load a remote Spring XML application context (leading to Runtime.exec() or similar execution on the JVM); affected ActiveMQ versions are before 5.19.4 and 6.2.3, and federal agencies were ordered to remediate by April 30, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.