logo

Apache ActiveMQ CVE-2026-34197 Added to CISA KEV Amid Active Exploitation

ID: f6d6ea31-ed8f-5b3e-832d-2a53a705cd2c

STIX ID: report--f6d6ea31-ed8f-5b3e-832d-2a53a705cd2c

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-04-17

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

CISA added CVE-2026-34197 (CVSS 8.8), an Apache ActiveMQ Classic Jolokia API input-validation flaw enabling remote code execution, to its Known Exploited Vulnerabilities list after reports of active targeting; affected versions include ActiveMQ before 5.19.4 and 6.0.0 before 6.2.3, and organizations are advised to upgrade, audit exposed Jolokia endpoints, enforce authentication, and disable Jolokia where not required.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.