logo

Apache ActiveMQ Patches RCE and Path Traversal Flaws

ID: 474c6885-68e5-5d95-8dff-bebc78a3f93d

STIX ID: report--474c6885-68e5-5d95-8dff-bebc78a3f93d

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-08

Date Updated: 2026-04-23

Author: Ddos

...
...

**Executive summary:** Apache ActiveMQ released critical fixes for two vulnerabilities: a high-severity RCE (CVE-2026-34197) in the Classic web console that leverages an overly permissive Jolokia policy and remote Spring XML loading to achieve arbitrary code execution by an authenticated attacker, and a lower-severity path traversal (CVE-2026-33227) that can expose sensitive files; affected 5.x and 6.x branches should be upgraded to 5.19.5/6.2.3 (RCE fix) and 5.19.4/6.2.2 (path traversal fix).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.