Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4305 articles · 196683 vulns · 37/41 feeds (7d)
← Back to list
8.8
CVE-2026-34197KEVEXPLOITEDPATCHED
apache · activemq

Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans

Description

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. Because Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec(). This issue affects Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ All: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.3. Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue

Affected Products

VendorProductVersions
apacheactivemq0, 6.0.0, 0, 6.0.0, 0, 6.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
apacheactivemq_brokercve_cpe95%
mavenorg.apache.activemq:activemq-brokerGHSA85%
mavenorg.apache.activemq:activemq-allGHSA85%

References

  • https://activemq.apache.org/security-advisories.data/CVE-2026-34197-announcement.txt(vendor-advisory)

Related News (23 articles)

Tier D
CSO Online17d ago
Human oversight is still critical as AI patching tools miss security risks
→ No new info (linked only)
Tier B
CERT-FR25d ago
Multiples vulnérabilités dans les produits IBM (31 juillet 2026)
→ No new info (linked only)
Tier B
CERT-FR32d ago
Multiples vulnérabilités dans les produits IBM (24 juillet 2026)
→ No new info (linked only)
Tier C
Rapid7 Blog80d ago
Weekly Metasploit Update: Apache ActiveMQ RCE, Gogs Rebase RCE, and Windows Kernel Pointer Enum
→ No new info (linked only)
Tier E
Lobsters Security101d ago
The First CVE Wave: Signs That AI-Assisted Vulnerability Discovery Is Reshaping Disclosure Volumes | Blog
→ No new info (linked only)
Tier C
oss-security123d ago
CVE-2026-40466: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Possible bypass of CVE-2026-34197 via HTTP discovery second-stage URI
→ No new info (linked only)
Tier D
The Hacker News123d ago
ThreatsDay Bulletin: $290M DeFi Hack, macOS LotL Abuse, ProxySmart SIM Farms +25 New Stories
→ No new info (linked only)
Tier D
CSO Online125d ago
Thousands of Apache ActiveMQ instances still unpatched, weeks after an actively exploited hole discovered
→ No new info (linked only)
Tier D
BleepingComputer125d ago
Actively exploited Apache ActiveMQ flaw impacts 6,400 servers
→ No new info (linked only)
Tier D
SecurityWeek129d ago
Recent Apache ActiveMQ Vulnerability Exploited in the Wild
→ No new info (linked only)
Tier D
Heise Security129d ago
Angreifer attackieren Apache ActiveMQ Broker, Apache ActiveMQ
→ No new info (linked only)
Tier D
BleepingComputer129d ago
CISA flags Apache ActiveMQ flaw as actively exploited in attacks
→ No new info (linked only)
Tier D
The Hacker News129d ago
Apache ActiveMQ CVE-2026-34197 Added to CISA KEV Amid Active Exploitation
→ No new info (linked only)
Tier D
Help Net Security134d ago
Week in review: Windows zero-day exploit leaked, Patch Tuesday forecast
→ No new info (linked only)
Tier D
CSO Online136d ago
Claude uncovers a 13‑year‑old ActiveMQ RCE bug within minutes
→ No new info (linked only)
Tier D
Help Net Security137d ago
Claude helps researcher dig up decade-old Apache ActiveMQ RCE vulnerability (CVE-2026-34197)
→ No new info (linked only)
Tier D
The Hacker News137d ago
ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories
→ No new info (linked only)
Tier B
CCCS Canada138d ago
Apache ActiveMQ security advisory (AV26-330)
→ No new info (linked only)
Tier D
BleepingComputer138d ago
13-year-old bug in ActiveMQ lets hackers remotely execute commands
→ No new info (linked only)
Tier D
Infosecurity Magazine138d ago
Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years
→ No new info (linked only)
Tier E
Reddit r/netsec139d ago
CVE-2026-34197: ActiveMQ RCE via Jolokia API
→ No new info (linked only)
Tier C
VulDB140d ago
CVE-2026-34197 | Apache ActiveMQ Broker/ActiveMQ Jolokia MBeans Remote Code Execution
→ No new info (linked only)
Tier C
oss-security140d ago
CVE-2026-34197: Apache ActiveMQ Broker, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
→ No new info (linked only)
CVSS 3.18.8 NONE
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
org.apache.activemq:activemq-broker@5.19.5org.apache.activemq:activemq-broker@6.2.3org.apache.activemq:activemq-all@5.19.5org.apache.activemq:activemq-all@6.2.3
CWECWE-20, CWE-94
PublishedApr 7, 2026
Last enriched80d agov12
Tags
RCEApache ActiveMQCVE-2026-34197CISA KEVCVE-2024-32114
Trending Score13
Source articles23
Independent14
Info Completeness12/14
Missing: epss, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-53434EXP
Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM Connector
Trending: 43
CRITICALCVE-2026-59084EXP
Apache Tomcat: EncryptInterceptor requirements not clearly documented
Trending: 37
HIGHCVE-2026-29167EXP
Apache HTTP Server: mod_ldap per-dir use-after-free
Trending: 37
HIGHCVE-2026-57819
Apache CXF: No default restriction on the amount of form parameters per message
Trending: 36
HIGHCVE-2026-64958
Apache CXF: Denial of service via message header attachments
Trending: 36

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 7, 2026
Added to CISA KEV
Apr 7, 2026
Discovered by ZDM
Apr 7, 2026
Updated: description, cweIds, tags
Apr 8, 2026
Updated: description, cweIds, tags
Apr 8, 2026
Updated: severity, activelyExploited
Apr 8, 2026
Updated: affectedVersions
Apr 10, 2026
Updated: description
Apr 10, 2026
Updated: tags
Apr 17, 2026
Updated: cweIds, tags
Apr 17, 2026
Updated: severity
Apr 17, 2026
Updated: iocs
Apr 21, 2026
Updated: description, severity
Jun 5, 2026
Updated: description, iocs
Jun 5, 2026
Actively Exploited
Aug 17, 2026
Exploit Available
Aug 17, 2026
Patch Available
Aug 17, 2026

Version History

v12
Last enriched 80d ago
v12Tier C80d ago

Updated description with more technical details and added a new IOC for the exploit.

descriptioniocs
via Rapid7 Blog
v11Tier C80d ago

Updated description with new exploit details and changed severity to HIGH.

descriptionseverity
via Rapid7 Blog
v10Tier D125d ago

Updated severity to HIGH, added information about over 6,400 vulnerable IP addresses, and included new tag CISA KEV.

iocs
via BleepingComputer
v9Tier D129d ago

Updated severity to HIGH and added CVE-2024-32114 as a related vulnerability.

severity
via SecurityWeek
v8Tier D129d ago

Updated severity to HIGH, added CWE-287, and included CVE-2024-32114 as a related vulnerability.

cweIdstags
via SecurityWeek
v7Tier D129d ago

Added CISA KEV tag and confirmed CVSS score as 8.8.

tags
via The Hacker News
v6Tier D136d ago

Updated description with more technical details and added affected version 6.1.1.

description
via CSO Online
v5Tier D136d ago

Updated description with more technical details and added affected version 6.1.1.

affectedVersions
via CSO Online
v4Tier B138d ago

Updated severity from NONE to HIGH and marked the vulnerability as actively exploited.

severityactivelyExploited
via CCCS Canada
v3Tier D138d ago

Updated description with new technical details, changed severity to HIGH, confirmed CVSS score of 8.8, added new CWE ID, marked as actively exploited, and included new IoCs and tags.

descriptioncweIdstags
via BleepingComputer
v2Tier D138d ago

Updated description with new technical details, changed severity to HIGH, added new CWEs, and included new IoCs and MITRE ATT&CK technique T1203.

descriptioncweIdstags
via Infosecurity Magazine
v1139d ago

Initial creation