13-year-old bug in ActiveMQ lets hackers remotely execute commands
ID: 570df788-c531-51c1-bf17-d29f4d6ab8f5
STIX ID: report--570df788-c531-51c1-bf17-d29f4d6ab8f5
Feed Name: Bleeping Computer
**Executive summary:** Security researchers disclosed CVE-2026-34197, a 13-year-old high-severity (CVSS 8.8) remote code execution vulnerability in Apache ActiveMQ Classic that allows attackers to force the broker to fetch a remote Spring XML via the Jolokia addNetworkConnector and execute system commands; it affects versions before 5.19.4 and all releases from 6.0.0 to 6.2.3, is unauthenticated on 6.0.0–6.1.1 due to a separate bug (CVE-2024-32114), and has been patched in ActiveMQ Classic 5.19.4 and 6.2.3 — organizations should apply updates and look for indicators such as VM transport connections and brokerConfig=xbean parameters in broker logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
