logo

Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years

ID: 60876be0-f3a1-5143-99a3-79ea683f2224

STIX ID: report--60876be0-f3a1-5143-99a3-79ea683f2224

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-04-08

Date Updated: 2026-04-22

...
...

A newly disclosed remote code execution vulnerability, **CVE-2026-34197**, in Apache ActiveMQ Classic allows attackers to invoke Jolokia management operations to fetch remote configuration files and execute arbitrary OS commands; on versions 6.0.0–6.1.1 the issue can be exploited without authentication due to CVE-2024-32114. Patches are available (5.19.4 and 6.2.3); operators should update, remove default credentials, and hunt for IOCs such as POSTs to /api/jolokia/ containing addNetworkConnector, outbound HTTP requests from the broker, vm:// URIs with brokerConfig=xbean:http, and unexpected child processes spawned by the ActiveMQ Java process.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.