Exploit discussion active in current signal (1 latest mentions)
Immediate actions
Patch apache activemq systems immediately
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: High priority (within 72h)
NVD description
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
A GitHub repository hosts an exploitation tool for multiple ActiveMQ CVEs, providing code and references, but does not mention active exploitation, patches, or false positive claims.
⚠️ **Vulnerability Alert:** Apache ActiveMQ — Consolidated RCE and Jolokia/OpenWire/Fileserver issues (CVE-2026-34197 + CVE-2024-32114 + CVE-2022-41678 + CVE-2023-46604 + CVE-2016-3088)
📅 **Timeline:** Disclosure: 2026-04-07, Patch: unknown
🆔 **CVE-2026-34197** | 📊 CVSS: 8.8 (HIGH 🟠) | 📈 EPSS: 18.84%
🆔 **CVE-2024-32114** | 📊 CVSS: 8.8 (HIGH 🟠) | 📈 EPSS: 83.74%
🆔 **CVE-2022-41678** | 📊 CVSS: 8.8 (HIGH 🟠) | 📈 EPSS: 99.84%
🆔 **CVE-2023-46604** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 99.99%
🆔 **CVE-2016-3088** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 99.94%
🛠️ **Exploit Maturity:** Proof-of-Concept (CVE-2026-34197); others vary (public exploits and known-exploited indications)
📂 **Affected Versions:** ActiveMQ Classic before 6.2.3 / before 5.19.4, ActiveMQ 6.0.0–6.1.1, Brokers/clients prior to 5.15.16/5.16.7/5.17.6/5.18.3, ActiveMQ 5.x before 5.14.0
🔧 **Fixed Versions:** 6.2.3, 5.19.5, 6.1.2, 5.16.6/5.17.4/5.18.0, 5.15.16/5.16.7/5.17.6/5.18.3
🫨 **Attack Vectors:**
- Jolokia HTTP-to-JMX addNetworkConnector with vm://brokerConfig=xbean -> remote Spring XML load -> bean instantiation -> RCE
- Unauthenticated Jolokia API (/api) in default ActiveMQ 6.0.0–6.1.1
- Jolokia ExecHandler / reflection-based exec via MBeans after authentication
- OpenWire Java marshaller deserialization/manipulation leading to class instantiation and RCE
- Fileserver webapp HTTP PUT + MOVE to upload and execute files
📝 **Summary:**
Multiple ActiveMQ flaws allow remote code execution via Jolokia (remote JMX calls and exec handlers), OpenWire marshaller deserialization, and legacy fileserver upload/MOVE abuse; some are exploitable remotely without authentication in default configs. Successful exploitation can run commands as the ActiveMQ process, manipulate messages, and lead to full host compromise or outbound fetches to attacker-controlled hosts.
📈 **Impact Scope:** Remote code execution as the broker process, potential full host compromise, unauthorized produce/consume/purge of messages, and observable outbound HTTP fetches; high real-world exploitability indicated by elevated EPSS for several CVEs.
🛡️ **Recommended Actions:**
- Apply vendor fixes immediately (see fixed versions above).
- If you cannot patch now: block access to API/web endpoints, restrict Jolokia, and require Jetty authentication.
- Rotate and audit broker credentials (remove default admin:admin) and block/monitor outbound HTTP from broker hosts.
- Hunt logs for vm:// brokerConfig=xbean indicators, unexpected child processes, and run host EDR/forensics on suspected systems.
🪢 **Related Resources:**
- https://horizon3.ai/intelligence/blogs/cve-2026-34197-activemq-rce-jolokia/
- https://activemq.apache.org/security-advisories.data/CVE-2026-34197-announcement.txt
🏷 **Tags:** #Cybersecurity#ApacheActiveMQ#RCE
Post summary
The post details new Apache ActiveMQ RCE vulnerabilities, provides PoCs, technical attack vectors, and recommends applying vendor patches and mitigations.