Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years
ID: 60876be0-f3a1-5143-99a3-79ea683f2224
STIX ID: report--60876be0-f3a1-5143-99a3-79ea683f2224
Feed Name: Infosecurity Magazine (News)
A newly disclosed remote code execution vulnerability, **CVE-2026-34197**, in Apache ActiveMQ Classic allows attackers to invoke Jolokia management operations to fetch remote configuration files and execute arbitrary OS commands; on versions 6.0.0–6.1.1 the issue can be exploited without authentication due to CVE-2024-32114. Patches are available (5.19.4 and 6.2.3); operators should update, remove default credentials, and hunt for IOCs such as POSTs to /api/jolokia/ containing addNetworkConnector, outbound HTTP requests from the broker, vm:// URIs with brokerConfig=xbean:http, and unexpected child processes spawned by the ActiveMQ Java process.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
