CVE-2025-66168Disclosure(apache / activemq)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache activemq systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

WARNING: Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases. See the  following for more details: https://activemq.apache.org/security-advisories.data/CVE-2026-40046-announcement.txt https://www.cve.org/CVERecord?id=CVE-2026-40046 Original Report: Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow during the decoding of malformed packets. When this integer overflow occurs, ActiveMQ may incorrectly compute the total Remaining Length and subsequently misinterpret the payload as multiple MQTT control packets which makes the broker susceptible to unexpected behavior when interacting with non-compliant clients. This behavior violates the MQTT v3.1.1 specification, which restricts Remaining Length to a maximum of 4 bytes. The scenario occurs on established connections after the authentication process. Brokers that are not enabling mqtt transport connectors are not impacted. This issue affects Apache ActiveMQ: before 5.19.2, 6.0.0 to 6.1.8, and 6.2.0 Users are recommended to upgrade to version 5.19.2, 6.1.9, or 6.2.1, which fixes the issue.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • activemq

Threat summary

  • Patch or workaround signal is available
  • 11 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 9 signals
  • Disclosure: 7 classified signals
  • General: 2 classified signals
  • Peaked 7d ago at 4 mentions (2026-03-04); latest day: 1
  • 11 total mentions across 8 days

Affected systems

Vendors
Products
activemq

1 version affected across 1 product

Deep dive

Activity timeline11 mentions / 8d
01234Mentions · 2026-03-04: 4Mentions · 2026-03-05: 1Mentions · 2026-03-08: 1Mentions · 2026-03-09: 1Mentions · 2026-03-10: 1Mentions · 2026-03-12: 1Mentions · 2026-04-09: 1Mentions · 2026-04-10: 1Patch / Workaround · 2026-03-05: 1Patch / Workaround · 2026-03-09: 1Patch / Workaround · 2026-04-09: 1Technical Details · 2026-03-04: 3Technical Details · 2026-03-05: 1Technical Details · 2026-03-08: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-12: 1Technical Details · 2026-04-09: 1Technical Details · 2026-04-10: 103-0403-0503-0803-0903-1003-1204-0904-10
Signal classification3 categories
Disclosure
763.6%
General
218.2%
Patch
218.2%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-03-044
Disclosure3General1
2026-03-051
Patch1
2026-03-081
Disclosure1
2026-03-091
Patch1
2026-03-101
General1
2026-03-121
Disclosure1
2026-04-091
Disclosure1
2026-04-101
Disclosure1
Full discourse11 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-27446: Apache Artemis, Apache ActiveMQ Artemis: Auth bypass for Core downstream federation https://www.openwall.com/lists/oss-security/2026/03/03/4 CVE-2025-66168: Apache ActiveMQ, All Module, MQTT Module: MQTT control packet remaining length field is not properly validated https://www.openwall.com/lists/oss-security/2026/03/03/5

    Post summary

    The passage announces two new CVEs affecting Apache Artemis/ActiveMQ, providing brief technical summaries and links to security mailing lists for further details.

    00040441
    4.4K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    Apache ActiveMQ CVE-2026-39304: Incorrect handling of TLSv1.3 KeyUpdate can be exploited to cause DoS via OOM https://www.openwall.com/lists/oss-security/2026/04/09/17 CVE-2026-40046: Missing fix for CVE-2025-66168: MQTT control packet remaining length field is not properly validated https://www.openwall.com/lists/oss-security/2026/04/09/18

    Post summary

    The text announces two Apache ActiveMQ CVEs, detailing DoS via TLSv1.3 KeyUpdate and a missing MQTT packet validation fix, without indicating PoCs, patches, or active exploitation.

    00010508
    4.4K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Apache ActiveMQ MQTT モジュールの脆弱性 CVE-2025-66168:整数オーバーフローと DoS 攻撃 https://iototsecnews.jp/2026/03/06/apache-activemq-allow-attackers-to-trigger-dos-attacks-with-malformed-packets/ 脆弱性 CVE-2025-66168 は、 Apache ActiveMQ の MQTT モジュールにおける数値処理の不備に起因します。通信の際に、データの長さを表すフィールドをプログラムが読み取るのですが、その値を適切にチェックしていなかったことで、計算結果が本来の型で扱える範囲を超えてしまう “整数オーバーフロー” という現象が起きてしまいます。これにより、サーバがパケットの大きさを正しく判断できなくなり、最終的にサービスの停止を招く恐れがあります。ご利用のチームは、ご注意ください。 #ActiveMQ #Apache #CVE202566168 #MQTT #Vulnerability

    Post summary

    Apache ActiveMQ’s MQTT module is vulnerable to an integer overflow that can trigger a DoS when handling malformed packets; the post offers no PoC, exploit, or patch, merely disclosing the issue.

    01000212
    484 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos Apache ❗ CVE-2025-66168 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-apache-8/ https://t.co/plKmUBdw1U

    Post summary

    The tweet announces the existence of CVE-2025-66168 affecting Apache products and directs readers to external links for more information.

    00001169
    6.6K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    An integer overflow flaw (CVE-2025-66168) in Apache ActiveMQ's MQTT module allows authenticated attackers to crash brokers. Update your systems immediately. #ApacheActiveMQ #CVE #CyberSecurity #MQTT #IoT #InfoSec #PatchAlert #DenialOfService #ThreatIntel https://securityonline.info/integer-overflow-flaw-in-apache-activemq-exposes-mqtt-brokers-to-dos/

    Post summary

    The tweet announces an integer overflow vulnerability in Apache ActiveMQ’s MQTT module capable of causing a denial‑of‑service and urges immediate updates to mitigate the risk.

    00010283
    10.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40046 Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT. The fix for "CVE-2025-66168: MQTT control packet remainin… https://www.cve.org/CVERecord?id=CVE-2026-40046

    Post summary

    The text announces the integer overflow vulnerability CVE-2026-40046 in Apache ActiveMQ and points to a URL that references the patch, but no PoC, exploit, or active exploitation is mentioned.

    00000171
    57.0K followersView on X
  • CinchOps@CinchOpsIT
    Patch

    ⚠️ 𝗔𝗽𝗮𝗰𝗵𝗲 𝗔𝗰𝘁𝗶𝘃𝗲𝗠𝗤 𝗩𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗶𝗹𝗶𝘁𝘆 𝗖𝗮𝗻 𝗞𝗻𝗼𝗰𝗸 𝗬𝗼𝘂𝗿 𝗦𝘆𝘀𝘁𝗲𝗺𝘀 𝗢𝗳𝗳𝗹𝗶𝗻𝗲 If your business runs Apache ActiveMQ - and a lot of SMBs do without realizing it - there's a new vulnerability worth knowing about. CVE-2025-66168 lets an authenticated attacker send a malformed network packet that triggers an integer overflow and takes your system down. No ransomware, no data theft - just your server going dark at the worst possible time. It affects all versions before 5.19.2 and a range of 6.x releases. The fix is a version upgrade, or if you can't patch immediately, disabling the MQTT transport connector buys you time. Either way, don't sit on this one. ❓Does your team know which software versions are running across your environment right now? 📲 If the answer is "not really," CinchOps can help you get a handle on it before something breaks. 🌐 http://cinchops.com/contact | 📲 281‑269‑6506 Full Article: https://cybersecuritynews.com/apache-activemq-dos-vulnerability/ #ITSupport #cybersecurity #HoustonSMB #PatchManagement #NetworkSecurity

    Post summary

    Apache ActiveMQ CVE‑2025‑66168 is a server‑crash integer overflow; patch by upgrading or disabling the MQTT connector.

    0000050
    5 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2025-66168 📊 Severity: 5.4 🚨 Risk Level: Medium 🚨 Affects: Apache Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-66168 #CVE-2025-66168 #CVE #Medium #Apache #CyberSecurity #InfoSec https://t.co/Fgdbp3tpCQ

    Post summary

    The tweet announces CVE-2025-66168, indicating a medium‑severity vulnerability affecting Apache, but provides no PoC, exploit code, patch, or active exploitation details.

    00000105
    64 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-66168 Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow during the decoding of malformed packets. When this integer overfl… https://www.cve.org/CVERecord?id=CVE-2025-66168 ----- Traducción: CVE-2025-66168 Apa… http://infoflow.cloud`

    Post summary

    The post announces CVE-2025-66168, describing an integer overflow in Apache ActiveMQ caused by improper validation of the remaining length field, but offers no PoC, exploit, or patch details.

    0000075
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-66168 Apache ActiveMQ does not properly validate the remaining length field which may lead to an overflow during the decoding of malformed packets. When this integer overfl… https://www.cve.org/CVERecord?id=CVE-2025-66168

    Post summary

    The text announces CVE-2025-66168, describing an integer overflow in Apache ActiveMQ due to improper validation of the remaining length field during packet decoding.

    00000305
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-66168 CVE-2025-66168 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-66168

    Post summary

    The text only references CVE-2025-66168 and provides a link to a vulnerability details page, with no additional information.

    0000076
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheactivemq---
Appapacheactivemq6.2.0--

Explore more