CVE-2016-3088Disclosure(apache / activemq)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apache activemq systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-08-10. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-434

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • activemq

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-07); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
activemq

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-07: 1Mentions · 2026-06-08: 1PoC Mentioned / Linked · 2026-04-07: 1PoC Mentioned / Linked · 2026-06-08: 1Exploit Tool / Code · 2026-06-08: 1Patch / Workaround · 2026-04-07: 1Technical Details · 2026-04-07: 104-0706-08
Signal classification2 categories
Disclosure
150.0%
Exploit
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-071
Disclosure1
2026-06-081
Exploit1
Full discourse2 posts
  • Clandestine@akaclandestine
    Exploit

    GitHub - Catherines77/ActiveMQ-EXPtools: Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588) · GitHub https://github.com/Catherines77/ActiveMQ-EXPtools

    Post summary

    A GitHub repository hosts an exploitation tool for multiple ActiveMQ CVEs, providing code and references, but does not mention active exploitation, patches, or false positive claims.

    013051324.4K
    62.7K followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** Apache ActiveMQ — Consolidated RCE and Jolokia/OpenWire/Fileserver issues (CVE-2026-34197 + CVE-2024-32114 + CVE-2022-41678 + CVE-2023-46604 + CVE-2016-3088) 📅 **Timeline:** Disclosure: 2026-04-07, Patch: unknown 🆔 **CVE-2026-34197** | 📊 CVSS: 8.8 (HIGH 🟠) | 📈 EPSS: 18.84% 🆔 **CVE-2024-32114** | 📊 CVSS: 8.8 (HIGH 🟠) | 📈 EPSS: 83.74% 🆔 **CVE-2022-41678** | 📊 CVSS: 8.8 (HIGH 🟠) | 📈 EPSS: 99.84% 🆔 **CVE-2023-46604** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 99.99% 🆔 **CVE-2016-3088** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 99.94% 🛠️ **Exploit Maturity:** Proof-of-Concept (CVE-2026-34197); others vary (public exploits and known-exploited indications) 📂 **Affected Versions:** ActiveMQ Classic before 6.2.3 / before 5.19.4, ActiveMQ 6.0.0–6.1.1, Brokers/clients prior to 5.15.16/5.16.7/5.17.6/5.18.3, ActiveMQ 5.x before 5.14.0 🔧 **Fixed Versions:** 6.2.3, 5.19.5, 6.1.2, 5.16.6/5.17.4/5.18.0, 5.15.16/5.16.7/5.17.6/5.18.3 🫨 **Attack Vectors:** - Jolokia HTTP-to-JMX addNetworkConnector with vm://brokerConfig=xbean -> remote Spring XML load -> bean instantiation -> RCE - Unauthenticated Jolokia API (/api) in default ActiveMQ 6.0.0–6.1.1 - Jolokia ExecHandler / reflection-based exec via MBeans after authentication - OpenWire Java marshaller deserialization/manipulation leading to class instantiation and RCE - Fileserver webapp HTTP PUT + MOVE to upload and execute files 📝 **Summary:** Multiple ActiveMQ flaws allow remote code execution via Jolokia (remote JMX calls and exec handlers), OpenWire marshaller deserialization, and legacy fileserver upload/MOVE abuse; some are exploitable remotely without authentication in default configs. Successful exploitation can run commands as the ActiveMQ process, manipulate messages, and lead to full host compromise or outbound fetches to attacker-controlled hosts. 📈 **Impact Scope:** Remote code execution as the broker process, potential full host compromise, unauthorized produce/consume/purge of messages, and observable outbound HTTP fetches; high real-world exploitability indicated by elevated EPSS for several CVEs. 🛡️ **Recommended Actions:** - Apply vendor fixes immediately (see fixed versions above). - If you cannot patch now: block access to API/web endpoints, restrict Jolokia, and require Jetty authentication. - Rotate and audit broker credentials (remove default admin:admin) and block/monitor outbound HTTP from broker hosts. - Hunt logs for vm:// brokerConfig=xbean indicators, unexpected child processes, and run host EDR/forensics on suspected systems. 🪢 **Related Resources:** - https://horizon3.ai/intelligence/blogs/cve-2026-34197-activemq-rce-jolokia/ - https://activemq.apache.org/security-advisories.data/CVE-2026-34197-announcement.txt 🏷 **Tags:** #Cybersecurity #ApacheActiveMQ #RCE

    Post summary

    The post details new Apache ActiveMQ RCE vulnerabilities, provides PoCs, technical attack vectors, and recommends applying vendor patches and mitigations.

    0001062
    276 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheactivemq---

Explore more