Apache ActiveMQ Patches RCE and Path Traversal Flaws
ID: 474c6885-68e5-5d95-8dff-bebc78a3f93d
STIX ID: report--474c6885-68e5-5d95-8dff-bebc78a3f93d
Feed Name: securityonline.info
**Executive summary:** Apache ActiveMQ released critical fixes for two vulnerabilities: a high-severity RCE (CVE-2026-34197) in the Classic web console that leverages an overly permissive Jolokia policy and remote Spring XML loading to achieve arbitrary code execution by an authenticated attacker, and a lower-severity path traversal (CVE-2026-33227) that can expose sensitive files; affected 5.x and 6.x branches should be upgraded to 5.19.5/6.2.3 (RCE fix) and 5.19.4/6.2.2 (path traversal fix).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
