logo

Apache ActiveMQ Vulnerabilities Allow Denial of Service and Takeover

ID: 9d60b3ca-cffd-5d33-aedf-3124eab3b0d3

STIX ID: report--9d60b3ca-cffd-5d33-aedf-3124eab3b0d3

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-07-03

Date Updated: 2026-08-06

Author: Do Son

ADMIRALTY:B6
...
...

Apache patched multiple ActiveMQ vulnerabilities across the 5.x and 6.x lines (fixed in 5.19.8 and 6.2.7) that include unauthenticated DoS vectors, access/authorization failures allowing one connection to consume another's temporary destination, a Web Console stored XSS, and LDAP connector abuse; administrators should urgently upgrade, restrict broker/Web Console access, enable authentication, and review LDAP filters despite no public proof-of-concept or observed exploitation to date.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.