Exploitation ongoing with high activity in latest observed window (1 mentions)
Immediate actions
Patch apache activemq systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: Immediate (within 24h)
NVD description
Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution.
In details, in ActiveMQ configurations, jetty allows
org.jolokia.http.AgentServlet to handler request to /api/jolokia
org.jolokia.http.HttpRequestHandler#handlePostRequest is able to
create JmxRequest through JSONObject. And calls to
org.jolokia.http.HttpRequestHandler#executeRequest.
Into deeper calling stacks,
org.jolokia.handler.ExecHandler#doHandleRequest can be invoked
through refection. This could lead to RCE through via
various mbeans. One example is unrestricted deserialization in jdk.management.jfr.FlightRecorderMXBeanImpl which exists on Java version above 11.
1 Call newRecording.
2 Call setConfiguration. And a webshell data hides in it.
3 Call startRecording.
4 Call copyTo method. The webshell will be written to a .jsp file.
The mitigation is to restrict (by default) the actions authorized on Jolokia, or disable Jolokia.
A more restrictive Jolokia configuration has been defined in default ActiveMQ distribution. We encourage users to upgrade to ActiveMQ distributions version including updated Jolokia configuration: 5.16.6, 5.17.4, 5.18.0, 6.0.0.
🚨 CVE-2022-41678 - high 🚨
Apache ActiveMQ < 5.16.5/5.17.3 - Remote Code Execution
> Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code e...
👾 https://cloud.projectdiscovery.io/library/CVE-2022-41678
@pdnuclei#NucleiTemplates#cve
Post summary
The tweet announces CVE-2022-41678 as a high‑severity remote code execution flaw affecting Apache ActiveMQ versions prior to 5.16.5/5.17.3, noting that authenticated users on Jolokia can potentially trigger arbitrary code execution.
The article reports that an AI system uncovered a long‑standing remote code execution flaw in ActiveMQ’s Jolokia API (CVE‑2026‑34197), explains the misconfiguration and authentication bypass that enabled the vulnerability, and warns users to be cautious.
⚠️ **Vulnerability Alert:** Apache ActiveMQ — Consolidated RCE and Jolokia/OpenWire/Fileserver issues (CVE-2026-34197 + CVE-2024-32114 + CVE-2022-41678 + CVE-2023-46604 + CVE-2016-3088)
📅 **Timeline:** Disclosure: 2026-04-07, Patch: unknown
🆔 **CVE-2026-34197** | 📊 CVSS: 8.8 (HIGH 🟠) | 📈 EPSS: 18.84%
🆔 **CVE-2024-32114** | 📊 CVSS: 8.8 (HIGH 🟠) | 📈 EPSS: 83.74%
🆔 **CVE-2022-41678** | 📊 CVSS: 8.8 (HIGH 🟠) | 📈 EPSS: 99.84%
🆔 **CVE-2023-46604** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 99.99%
🆔 **CVE-2016-3088** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 99.94%
🛠️ **Exploit Maturity:** Proof-of-Concept (CVE-2026-34197); others vary (public exploits and known-exploited indications)
📂 **Affected Versions:** ActiveMQ Classic before 6.2.3 / before 5.19.4, ActiveMQ 6.0.0–6.1.1, Brokers/clients prior to 5.15.16/5.16.7/5.17.6/5.18.3, ActiveMQ 5.x before 5.14.0
🔧 **Fixed Versions:** 6.2.3, 5.19.5, 6.1.2, 5.16.6/5.17.4/5.18.0, 5.15.16/5.16.7/5.17.6/5.18.3
🫨 **Attack Vectors:**
- Jolokia HTTP-to-JMX addNetworkConnector with vm://brokerConfig=xbean -> remote Spring XML load -> bean instantiation -> RCE
- Unauthenticated Jolokia API (/api) in default ActiveMQ 6.0.0–6.1.1
- Jolokia ExecHandler / reflection-based exec via MBeans after authentication
- OpenWire Java marshaller deserialization/manipulation leading to class instantiation and RCE
- Fileserver webapp HTTP PUT + MOVE to upload and execute files
📝 **Summary:**
Multiple ActiveMQ flaws allow remote code execution via Jolokia (remote JMX calls and exec handlers), OpenWire marshaller deserialization, and legacy fileserver upload/MOVE abuse; some are exploitable remotely without authentication in default configs. Successful exploitation can run commands as the ActiveMQ process, manipulate messages, and lead to full host compromise or outbound fetches to attacker-controlled hosts.
📈 **Impact Scope:** Remote code execution as the broker process, potential full host compromise, unauthorized produce/consume/purge of messages, and observable outbound HTTP fetches; high real-world exploitability indicated by elevated EPSS for several CVEs.
🛡️ **Recommended Actions:**
- Apply vendor fixes immediately (see fixed versions above).
- If you cannot patch now: block access to API/web endpoints, restrict Jolokia, and require Jetty authentication.
- Rotate and audit broker credentials (remove default admin:admin) and block/monitor outbound HTTP from broker hosts.
- Hunt logs for vm:// brokerConfig=xbean indicators, unexpected child processes, and run host EDR/forensics on suspected systems.
🪢 **Related Resources:**
- https://horizon3.ai/intelligence/blogs/cve-2026-34197-activemq-rce-jolokia/
- https://activemq.apache.org/security-advisories.data/CVE-2026-34197-announcement.txt
🏷 **Tags:** #Cybersecurity#ApacheActiveMQ#RCE
Post summary
Apache ActiveMQ is affected by multiple high‑severity CVEs, notably CVE‑2026‑34197, with confirmed public PoC exploits and evidence of in‑the‑wild activity, necessitating immediate patching or mitigation.