Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2444 articles · 160559 vulns · 36/41 feeds (7d)
← Back to list
8.8
CVE-2026-34197KEVEXPLOITEDPATCHED
apache · activemq

Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans

Description

Adds a new exploit module exploit/multi/http/apache_activemq_jolokia_rce targeting CVE-2026-34197 in Apache ActiveMQ. The module abuses the Jolokia JMX-over-HTTP API exposed at /api/jolokia/ by calling the addNetworkConnector() MBean operation with a crafted brokerConfig=xbean:http://... URI. ActiveMQ fetches the attacker-controlled URL and instantiates it as a Spring XML application context, achieving remote code execution via a java.lang.ProcessBuilder bean. Authentication is required to exploit this vulnerability.

Affected Products

VendorProductVersions
apacheactivemq0, 6.0.0, 0, 6.0.0, 0, 6.0.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
apacheactivemq_brokercve_cpe95%
mavenorg.apache.activemq:activemq-brokerGHSA85%
mavenorg.apache.activemq:activemq-allGHSA85%

References

  • https://activemq.apache.org/security-advisories.data/CVE-2026-34197-announcement.txt(vendor-advisory)

Related News (20 articles)

Tier C
Rapid7 Blog8h ago
Weekly Metasploit Update: Apache ActiveMQ RCE, Gogs Rebase RCE, and Windows Kernel Pointer Enum
→ No new info (linked only)
Tier E
Lobsters Security21d ago
The First CVE Wave: Signs That AI-Assisted Vulnerability Discovery Is Reshaping Disclosure Volumes | Blog
→ No new info (linked only)
Tier C
oss-security43d ago
CVE-2026-40466: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Possible bypass of CVE-2026-34197 via HTTP discovery second-stage URI
→ No new info (linked only)
Tier D
The Hacker News43d ago
ThreatsDay Bulletin: $290M DeFi Hack, macOS LotL Abuse, ProxySmart SIM Farms +25 New Stories
→ No new info (linked only)
Tier D
CSO Online45d ago
Thousands of Apache ActiveMQ instances still unpatched, weeks after an actively exploited hole discovered
→ No new info (linked only)
Tier D
BleepingComputer45d ago
Actively exploited Apache ActiveMQ flaw impacts 6,400 servers
→ No new info (linked only)
Tier D
SecurityWeek49d ago
Recent Apache ActiveMQ Vulnerability Exploited in the Wild
→ No new info (linked only)
Tier D
Heise Security49d ago
Angreifer attackieren Apache ActiveMQ Broker, Apache ActiveMQ
→ No new info (linked only)
Tier D
BleepingComputer49d ago
CISA flags Apache ActiveMQ flaw as actively exploited in attacks
→ No new info (linked only)
Tier D
The Hacker News49d ago
Apache ActiveMQ CVE-2026-34197 Added to CISA KEV Amid Active Exploitation
→ No new info (linked only)
Tier D
Help Net Security54d ago
Week in review: Windows zero-day exploit leaked, Patch Tuesday forecast
→ No new info (linked only)
Tier D
CSO Online56d ago
Claude uncovers a 13‑year‑old ActiveMQ RCE bug within minutes
→ No new info (linked only)
Tier D
Help Net Security57d ago
Claude helps researcher dig up decade-old Apache ActiveMQ RCE vulnerability (CVE-2026-34197)
→ No new info (linked only)
Tier D
The Hacker News57d ago
ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories
→ No new info (linked only)
Tier B
CCCS Canada58d ago
Apache ActiveMQ security advisory (AV26-330)
→ No new info (linked only)
Tier D
BleepingComputer58d ago
13-year-old bug in ActiveMQ lets hackers remotely execute commands
→ No new info (linked only)
Tier D
Infosecurity Magazine58d ago
Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years
→ No new info (linked only)
Tier E
Reddit r/netsec59d ago
CVE-2026-34197: ActiveMQ RCE via Jolokia API
→ No new info (linked only)
Tier C
VulDB60d ago
CVE-2026-34197 | Apache ActiveMQ Broker/ActiveMQ Jolokia MBeans Remote Code Execution
→ No new info (linked only)
Tier C
oss-security60d ago
CVE-2026-34197: Apache ActiveMQ Broker, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
→ No new info (linked only)
CVSS 3.18.8 HIGH
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
org.apache.activemq:activemq-broker@5.19.5org.apache.activemq:activemq-broker@6.2.3org.apache.activemq:activemq-all@5.19.5org.apache.activemq:activemq-all@6.2.3
CWECWE-20, CWE-94
PublishedApr 7, 2026
Last enriched2h agov12
Tags
RCEApache ActiveMQCVE-2026-34197CISA KEVCVE-2024-32114
Trending Score152🔥
Source articles20
Independent13
Info Completeness12/14
Missing: epss, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

MEDIUMCVE-2026-34479EXP
Apache Log4j 1 to Log4j 2 bridge: Silent log event loss in Log4j1XmlLayout due to unescaped XML 1.0 forbidden characters
Trending: 66
MEDIUMCVE-2026-34480EXP
Apache Log4j Core: Silent log event loss in XmlLayout due to unescaped XML 1.0 forbidden characters
Trending: 66
CRITICALCVE-2026-50076EXP
Apache Fory: Java ReplaceResolverSerializer deserialization checks bypass
Trending: 64
MEDIUMCVE-2026-34477EXP
Apache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypass
Trending: 57
MEDIUMCVE-2026-34478
Apache Log4j Core: Log injection in Rfc5424Layout due to silent configuration incompatibility
Trending: 48

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 7, 2026
Added to CISA KEV
Apr 7, 2026
Discovered by ZDM
Apr 7, 2026
Updated: description, cweIds, tags
Apr 8, 2026
Updated: description, cweIds, tags
Apr 8, 2026
Updated: severity, activelyExploited
Apr 8, 2026
Updated: affectedVersions
Apr 10, 2026
Updated: description
Apr 10, 2026
Updated: tags
Apr 17, 2026
Updated: cweIds, tags
Apr 17, 2026
Updated: severity
Apr 17, 2026
Updated: iocs
Apr 21, 2026
Actively Exploited
May 22, 2026
Exploit Available
May 22, 2026
Patch Available
May 22, 2026
Updated: description, severity
Jun 5, 2026
Updated: description, iocs
Jun 5, 2026

Version History

v12
Last enriched 2h ago
v12Tier C2h ago

Updated description with more technical details and added a new IOC for the exploit.

descriptioniocs
via Rapid7 Blog
v11Tier C2h ago

Updated description with new exploit details and changed severity to HIGH.

descriptionseverity
via Rapid7 Blog
v10Tier D45d ago

Updated severity to HIGH, added information about over 6,400 vulnerable IP addresses, and included new tag CISA KEV.

iocs
via BleepingComputer
v9Tier D49d ago

Updated severity to HIGH and added CVE-2024-32114 as a related vulnerability.

severity
via SecurityWeek
v8Tier D49d ago

Updated severity to HIGH, added CWE-287, and included CVE-2024-32114 as a related vulnerability.

cweIdstags
via SecurityWeek
v7Tier D49d ago

Added CISA KEV tag and confirmed CVSS score as 8.8.

tags
via The Hacker News
v6Tier D56d ago

Updated description with more technical details and added affected version 6.1.1.

description
via CSO Online
v5Tier D56d ago

Updated description with more technical details and added affected version 6.1.1.

affectedVersions
via CSO Online
v4Tier B58d ago

Updated severity from NONE to HIGH and marked the vulnerability as actively exploited.

severityactivelyExploited
via CCCS Canada
v3Tier D58d ago

Updated description with new technical details, changed severity to HIGH, confirmed CVSS score of 8.8, added new CWE ID, marked as actively exploited, and included new IoCs and tags.

descriptioncweIdstags
via BleepingComputer
v2Tier D58d ago

Updated description with new technical details, changed severity to HIGH, added new CWEs, and included new IoCs and MITRE ATT&CK technique T1203.

descriptioncweIdstags
via Infosecurity Magazine
v159d ago

Initial creation