CVE-2022-41678Disclosure(apache / activemq)

HIGHCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch apache activemq systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution.  In details, in ActiveMQ configurations, jetty allows org.jolokia.http.AgentServlet to handler request to /api/jolokia org.jolokia.http.HttpRequestHandler#handlePostRequest is able to create JmxRequest through JSONObject. And calls to org.jolokia.http.HttpRequestHandler#executeRequest. Into deeper calling stacks, org.jolokia.handler.ExecHandler#doHandleRequest can be invoked through refection. This could lead to RCE through via various mbeans. One example is unrestricted deserialization in jdk.management.jfr.FlightRecorderMXBeanImpl which exists on Java version above 11. 1 Call newRecording. 2 Call setConfiguration. And a webshell data hides in it. 3 Call startRecording. 4 Call copyTo method. The webshell will be written to a .jsp file. The mitigation is to restrict (by default) the actions authorized on Jolokia, or disable Jolokia. A more restrictive Jolokia configuration has been defined in default ActiveMQ distribution. We encourage users to upgrade to ActiveMQ distributions version including updated Jolokia configuration: 5.16.6, 5.17.4, 5.18.0, 6.0.0.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • activemq

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-04-01); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
activemq

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-04-01: 1Mentions · 2026-04-07: 1Mentions · 2026-04-16: 1Mentions · 2026-06-08: 1PoC Mentioned / Linked · 2026-04-07: 1PoC Mentioned / Linked · 2026-06-08: 1Exploit Tool / Code · 2026-04-07: 1Exploit Tool / Code · 2026-06-08: 1Active Exploitation · 2026-04-07: 1Patch / Workaround · 2026-04-07: 1Technical Details · 2026-04-01: 1Technical Details · 2026-04-07: 1Technical Details · 2026-04-16: 104-0104-0704-1606-08
Signal classification3 categories
Disclosure
250.0%
Active Exploitation
125.0%
Exploit
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-011
Disclosure1
2026-04-071
Active Exploitation1
2026-04-161
Disclosure1
2026-06-081
Exploit1
Full discourse4 posts
  • Clandestine@akaclandestine
    Exploit

    GitHub - Catherines77/ActiveMQ-EXPtools: Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588) · GitHub https://github.com/Catherines77/ActiveMQ-EXPtools

    Post summary

    The GitHub repository hosts an exploitation toolkit for multiple ActiveMQ CVEs, offering functional exploit code.

    013051324.4K
    62.7K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2022-41678 - high 🚨 Apache ActiveMQ < 5.16.5/5.17.3 - Remote Code Execution > Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code e... 👾 https://cloud.projectdiscovery.io/library/CVE-2022-41678 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE-2022-41678 as a high‑severity remote code execution flaw affecting Apache ActiveMQ versions prior to 5.16.5/5.17.3, noting that authenticated users on Jolokia can potentially trigger arbitrary code execution.

    00011140
    905 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    ActiveMQ Jolokia API の RCE 脆弱性 CVE-2026-34197 が FIX:13 年放置の問題を AI が 10 分で発見 https://iototsecnews.jp/2026/04/08/claude-uncovers-13-year-old-rce-flaw-in-apache-activemq-in-just-10-minutes/ この脆弱性 CVE-2026-34197 は、過去の修正によって生まれた設定の不備に起因するものです。過去における CVE-2022-41678 の修正時に、利便性を優先して幅広い操作を許可してしまったことで、本来は制限されるべき管理機能が外部から呼び出せる状態になっていました。それに加えて CVE-2024-32114 の影響で認証を回避できてしまう環境があったことも、被害のリスクを高める要因となりました。ご利用のチームは、ご注意ください。 #ActiveMQ #AI #ML #Apache #CVE202634197 #Vulnerability

    Post summary

    The article reports that an AI system uncovered a long‑standing remote code execution flaw in ActiveMQ’s Jolokia API (CVE‑2026‑34197), explains the misconfiguration and authentication bypass that enabled the vulnerability, and warns users to be cautious.

    01000113
    484 followersView on X
  • Syed Aquib@syedaquib77
    Active Exploitation

    ⚠️ **Vulnerability Alert:** Apache ActiveMQ — Consolidated RCE and Jolokia/OpenWire/Fileserver issues (CVE-2026-34197 + CVE-2024-32114 + CVE-2022-41678 + CVE-2023-46604 + CVE-2016-3088) 📅 **Timeline:** Disclosure: 2026-04-07, Patch: unknown 🆔 **CVE-2026-34197** | 📊 CVSS: 8.8 (HIGH 🟠) | 📈 EPSS: 18.84% 🆔 **CVE-2024-32114** | 📊 CVSS: 8.8 (HIGH 🟠) | 📈 EPSS: 83.74% 🆔 **CVE-2022-41678** | 📊 CVSS: 8.8 (HIGH 🟠) | 📈 EPSS: 99.84% 🆔 **CVE-2023-46604** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 99.99% 🆔 **CVE-2016-3088** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 99.94% 🛠️ **Exploit Maturity:** Proof-of-Concept (CVE-2026-34197); others vary (public exploits and known-exploited indications) 📂 **Affected Versions:** ActiveMQ Classic before 6.2.3 / before 5.19.4, ActiveMQ 6.0.0–6.1.1, Brokers/clients prior to 5.15.16/5.16.7/5.17.6/5.18.3, ActiveMQ 5.x before 5.14.0 🔧 **Fixed Versions:** 6.2.3, 5.19.5, 6.1.2, 5.16.6/5.17.4/5.18.0, 5.15.16/5.16.7/5.17.6/5.18.3 🫨 **Attack Vectors:** - Jolokia HTTP-to-JMX addNetworkConnector with vm://brokerConfig=xbean -> remote Spring XML load -> bean instantiation -> RCE - Unauthenticated Jolokia API (/api) in default ActiveMQ 6.0.0–6.1.1 - Jolokia ExecHandler / reflection-based exec via MBeans after authentication - OpenWire Java marshaller deserialization/manipulation leading to class instantiation and RCE - Fileserver webapp HTTP PUT + MOVE to upload and execute files 📝 **Summary:** Multiple ActiveMQ flaws allow remote code execution via Jolokia (remote JMX calls and exec handlers), OpenWire marshaller deserialization, and legacy fileserver upload/MOVE abuse; some are exploitable remotely without authentication in default configs. Successful exploitation can run commands as the ActiveMQ process, manipulate messages, and lead to full host compromise or outbound fetches to attacker-controlled hosts. 📈 **Impact Scope:** Remote code execution as the broker process, potential full host compromise, unauthorized produce/consume/purge of messages, and observable outbound HTTP fetches; high real-world exploitability indicated by elevated EPSS for several CVEs. 🛡️ **Recommended Actions:** - Apply vendor fixes immediately (see fixed versions above). - If you cannot patch now: block access to API/web endpoints, restrict Jolokia, and require Jetty authentication. - Rotate and audit broker credentials (remove default admin:admin) and block/monitor outbound HTTP from broker hosts. - Hunt logs for vm:// brokerConfig=xbean indicators, unexpected child processes, and run host EDR/forensics on suspected systems. 🪢 **Related Resources:** - https://horizon3.ai/intelligence/blogs/cve-2026-34197-activemq-rce-jolokia/ - https://activemq.apache.org/security-advisories.data/CVE-2026-34197-announcement.txt 🏷 **Tags:** #Cybersecurity #ApacheActiveMQ #RCE

    Post summary

    Apache ActiveMQ is affected by multiple high‑severity CVEs, notably CVE‑2026‑34197, with confirmed public PoC exploits and evidence of in‑the‑wild activity, necessitating immediate patching or mitigation.

    0001062
    276 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheactivemq---

Explore more