Apache ActiveMQ Patches “OOM” and MQTT Protocol Flaws
ID: 6166557c-fae2-53cb-9dac-d9a861d004f8
STIX ID: report--6166557c-fae2-53cb-9dac-d9a861d004f8
Feed Name: securityonline.info
Threat Score
Apache ActiveMQ issued critical updates for multiple vulnerabilities: CVE-2026-39304 (Important) enables a malicious TLSv1.3 client to force frequent KeyUpdate processing and exhaust broker memory causing an OOM DoS, and CVE-2026-40046 represents a regression that reintroduced an MQTT integer overflow; administrators are advised to upgrade 6.x to 6.2.4+ and 5.x to 5.19.5+.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
