logo

CISA flags Apache ActiveMQ flaw as actively exploited in attacks

ID: 03393961-4811-5f3f-b6aa-a27704636dd8

STIX ID: report--03393961-4811-5f3f-b6aa-a27704636dd8

Feed Name: Bleeping Computer

Threat Score
82/100

Date Published: 2026-04-17

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Apache ActiveMQ suffers a high-severity RCE vulnerability (CVE-2026-34197) — present for 13 years — that was patched in ActiveMQ Classic 6.2.3 and 5.19.4; CISA reports active exploitation, added the CVE to its KEV catalog, and ordered federal agencies to patch within two weeks. ShadowServer reports over 7,500 exposed ActiveMQ servers, Horizon3 provided detection guidance (suspicious brokerConfig=xbean:http:// connections and VM transport usage), and organizations are urged to prioritize mitigation or discontinuation if mitigations are unavailable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.