logo

13-year-old bug in ActiveMQ lets hackers remotely execute commands

ID: 570df788-c531-51c1-bf17-d29f4d6ab8f5

STIX ID: report--570df788-c531-51c1-bf17-d29f4d6ab8f5

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-04-08

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Executive summary:** Security researchers disclosed CVE-2026-34197, a 13-year-old high-severity (CVSS 8.8) remote code execution vulnerability in Apache ActiveMQ Classic that allows attackers to force the broker to fetch a remote Spring XML via the Jolokia addNetworkConnector and execute system commands; it affects versions before 5.19.4 and all releases from 6.0.0 to 6.2.3, is unauthenticated on 6.0.0–6.1.1 due to a separate bug (CVE-2024-32114), and has been patched in ActiveMQ Classic 5.19.4 and 6.2.3 — organizations should apply updates and look for indicators such as VM transport connections and brokerConfig=xbean parameters in broker logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.