Actively exploited Apache ActiveMQ flaw impacts 6,400 servers
ID: 83677bb6-8f4a-5563-ab02-ed73f4f56fe4
STIX ID: report--83677bb6-8f4a-5563-ab02-ed73f4f56fe4
Feed Name: Bleeping Computer
Shadowserver and CISA warn that CVE-2026-34197 — a high-severity code-injection flaw in Apache ActiveMQ enabling authenticated arbitrary code execution — is being actively exploited; more than 6,400 exposed ActiveMQ servers were identified worldwide. Apache released patches (ActiveMQ Classic 6.2.3 and 5.19.4) on March 30 and administrators are urged to apply patches or mitigations and search broker logs for exploitation indicators (VM internal transport, brokerConfig=xbean:http://).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
