U.S. CISA adds a flaw in Apache ActiveMQ to its Known Exploited Vulnerabilities catalog
ID: 59da6300-d636-595d-bdba-3b1fc4e780b5
STIX ID: report--59da6300-d636-595d-bdba-3b1fc4e780b5
Feed Name: Security Affairs
Threat Score
CISA has added CVE-2026-34197 — a critical (CVSS 8.8) remote code execution flaw in Apache ActiveMQ’s Jolokia JMX-HTTP bridge — to its Known Exploited Vulnerabilities catalog. Authenticated attackers can craft requests that cause the broker to load a remote Spring XML application context (leading to Runtime.exec() or similar execution on the JVM); affected ActiveMQ versions are before 5.19.4 and 6.2.3, and federal agencies were ordered to remediate by April 30, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
