logo

CISA Adds Critical Apache ActiveMQ RCE Flaw to KEV Catalog

ID: d5ee7de2-ab30-555f-af6e-7891e16787f5

STIX ID: report--d5ee7de2-ab30-555f-af6e-7891e16787f5

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-04-17

Date Updated: 2026-04-23

Author: Ddos

...
...

CVE-2026-34197 is a high-severity (CVSS 8.8) remote code execution vulnerability in Apache ActiveMQ’s Jolokia JMX-HTTP bridge (exposed at /api/jolokia/) that allows authenticated attackers to invoke broker operations (e.g., BrokerService.addConnector) with crafted URIs to load remote Spring XML contexts and execute arbitrary code on the broker JVM; CISA has added it to the Known Exploited Vulnerabilities catalog, reports active weaponization, lists affected versions and fixed releases (5.19.4 and 6.2.3), and ordered federal remediation by April 30, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.