CVE-2026-34197Active Exploitation(apache / activemq)

CRITICALCVSS 8.8 · HIGHCISA KEV

Exploitation observed; activity peaked at 61 mentions and remains active

Immediate actions

  • Patch apache activemq systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. Because Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec(). This issue affects Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ All: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.3. Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-04-30. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-20CWE-94CWE-78

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • activemq
  • activemq_broker

Threat summary

  • Active exploitation appears in 130 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 242 mentions across 47 observed days

What's happening

  • Active exploitation reported across 130 signals
  • Exploit tool or code specified in 9 signals
  • PoC mentioned or linked in 24 signals
  • Patch or workaround mentioned in 96 signals
  • Technical details provided in 165 signals
  • Disclosure: 49 classified signals
  • Peaked 36d ago at 61 mentions (2026-04-17); latest day: 1
  • 242 total mentions across 47 days

Affected systems

Vendors
Products
activemqactivemq_broker

Deep dive

Activity timeline242 mentions / 47d
015314661Mentions · 2026-04-07: 8Mentions · 2026-04-08: 18Mentions · 2026-04-09: 15Mentions · 2026-04-10: 6Mentions · 2026-04-11: 1Mentions · 2026-04-12: 1Mentions · 2026-04-13: 4Mentions · 2026-04-14: 1Mentions · 2026-04-15: 2Mentions · 2026-04-16: 8Mentions · 2026-04-17: 61Mentions · 2026-04-18: 14Mentions · 2026-04-19: 14Mentions · 2026-04-20: 18Mentions · 2026-04-21: 11Mentions · 2026-04-22: 5Mentions · 2026-04-23: 4Mentions · 2026-04-24: 2Mentions · 2026-04-25: 2Mentions · 2026-04-26: 2Mentions · 2026-04-27: 1Mentions · 2026-04-28: 4Mentions · 2026-04-29: 1Mentions · 2026-04-30: 4Mentions · 2026-05-01: 3Mentions · 2026-05-02: 1Mentions · 2026-05-06: 2Mentions · 2026-05-07: 1Mentions · 2026-05-14: 1Mentions · 2026-05-15: 3Mentions · 2026-05-16: 1Mentions · 2026-05-19: 1Mentions · 2026-05-21: 3Mentions · 2026-05-25: 1Mentions · 2026-06-06: 1Mentions · 2026-06-08: 1Mentions · 2026-06-09: 1Mentions · 2026-06-12: 1Mentions · 2026-06-24: 5Mentions · 2026-07-02: 1Mentions · 2026-07-03: 1Mentions · 2026-07-04: 2Mentions · 2026-07-31: 1Mentions · 2026-10-02: 1Mentions · 2026-10-06: 1Mentions · 2026-10-07: 1Mentions · 2026-10-08: 1PoC Mentioned / Linked · 2026-04-07: 2PoC Mentioned / Linked · 2026-04-08: 5PoC Mentioned / Linked · 2026-04-09: 2PoC Mentioned / Linked · 2026-04-11: 1PoC Mentioned / Linked · 2026-04-13: 1PoC Mentioned / Linked · 2026-04-17: 2PoC Mentioned / Linked · 2026-04-19: 1PoC Mentioned / Linked · 2026-04-20: 1PoC Mentioned / Linked · 2026-05-07: 1PoC Mentioned / Linked · 2026-05-14: 1PoC Mentioned / Linked · 2026-05-15: 2PoC Mentioned / Linked · 2026-06-06: 1PoC Mentioned / Linked · 2026-06-08: 1PoC Mentioned / Linked · 2026-06-09: 1PoC Mentioned / Linked · 2026-07-03: 1PoC Mentioned / Linked · 2026-07-04: 1Exploit Tool / Code · 2026-04-08: 1Exploit Tool / Code · 2026-04-09: 1Exploit Tool / Code · 2026-04-17: 1Exploit Tool / Code · 2026-05-07: 1Exploit Tool / Code · 2026-06-06: 1Exploit Tool / Code · 2026-06-08: 1Exploit Tool / Code · 2026-06-09: 1Exploit Tool / Code · 2026-07-02: 1Exploit Tool / Code · 2026-07-04: 1Active Exploitation · 2026-04-08: 1Active Exploitation · 2026-04-09: 3Active Exploitation · 2026-04-16: 3Active Exploitation · 2026-04-17: 57Active Exploitation · 2026-04-18: 11Active Exploitation · 2026-04-19: 8Active Exploitation · 2026-04-20: 13Active Exploitation · 2026-04-21: 8Active Exploitation · 2026-04-22: 5Active Exploitation · 2026-04-23: 3Active Exploitation · 2026-04-24: 2Active Exploitation · 2026-04-25: 2Active Exploitation · 2026-04-26: 1Active Exploitation · 2026-04-28: 1Active Exploitation · 2026-04-30: 1Active Exploitation · 2026-05-01: 1Active Exploitation · 2026-05-02: 1Active Exploitation · 2026-05-07: 1Active Exploitation · 2026-05-14: 1Active Exploitation · 2026-05-15: 2Active Exploitation · 2026-05-16: 1Active Exploitation · 2026-05-21: 3Active Exploitation · 2026-06-12: 1Patch / Workaround · 2026-04-07: 2Patch / Workaround · 2026-04-08: 10Patch / Workaround · 2026-04-09: 2Patch / Workaround · 2026-04-10: 2Patch / Workaround · 2026-04-13: 3Patch / Workaround · 2026-04-15: 1Patch / Workaround · 2026-04-16: 2Patch / Workaround · 2026-04-17: 26Patch / Workaround · 2026-04-18: 5Patch / Workaround · 2026-04-19: 8Patch / Workaround · 2026-04-20: 3Patch / Workaround · 2026-04-21: 8Patch / Workaround · 2026-04-22: 2Patch / Workaround · 2026-04-23: 3Patch / Workaround · 2026-04-24: 1Patch / Workaround · 2026-04-26: 2Patch / Workaround · 2026-04-29: 1Patch / Workaround · 2026-04-30: 3Patch / Workaround · 2026-05-01: 1Patch / Workaround · 2026-05-02: 1Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-05-15: 1Patch / Workaround · 2026-05-19: 1Patch / Workaround · 2026-05-21: 3Patch / Workaround · 2026-06-06: 1Patch / Workaround · 2026-07-02: 1Patch / Workaround · 2026-07-03: 1Patch / Workaround · 2026-07-04: 1Technical Details · 2026-04-07: 8Technical Details · 2026-04-08: 17Technical Details · 2026-04-09: 15Technical Details · 2026-04-10: 6Technical Details · 2026-04-11: 1Technical Details · 2026-04-12: 1Technical Details · 2026-04-13: 4Technical Details · 2026-04-14: 1Technical Details · 2026-04-16: 5Technical Details · 2026-04-17: 32Technical Details · 2026-04-18: 8Technical Details · 2026-04-19: 11Technical Details · 2026-04-20: 15Technical Details · 2026-04-21: 6Technical Details · 2026-04-22: 1Technical Details · 2026-04-23: 2Technical Details · 2026-04-24: 1Technical Details · 2026-04-25: 1Technical Details · 2026-04-26: 2Technical Details · 2026-04-27: 1Technical Details · 2026-04-28: 3Technical Details · 2026-04-29: 1Technical Details · 2026-04-30: 3Technical Details · 2026-05-01: 1Technical Details · 2026-05-06: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-15: 2Technical Details · 2026-05-19: 1Technical Details · 2026-05-21: 2Technical Details · 2026-05-25: 1Technical Details · 2026-06-06: 1Technical Details · 2026-06-09: 1Technical Details · 2026-06-12: 1Technical Details · 2026-06-24: 4Technical Details · 2026-07-02: 1Technical Details · 2026-07-03: 1Technical Details · 2026-07-04: 204-0704-1104-1504-1904-2304-2705-0105-1405-2106-0907-0310-0610-08
Signal classification6 categories
Active Exploitation
12452.1%
Disclosure
4920.6%
Patch
3313.9%
General
187.6%
PoC
104.2%
Exploit
41.7%
Referenced assets174 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-078
Disclosure7PoC1
2026-04-0818
Active Exploitation1Disclosure9General1Patch5PoC2
2026-04-0915
Active Exploitation3Disclosure7General3Patch1PoC1
2026-04-106
Disclosure3General1Patch2
2026-04-111
PoC1
2026-04-121
Disclosure1
2026-04-134
Disclosure1Patch3
2026-04-141
Disclosure1
2026-04-152
General1Patch1
2026-04-168
Active Exploitation3Disclosure3Patch2
2026-04-1761
Active Exploitation52Disclosure1Exploit1General1Patch6
2026-04-1814
Active Exploitation11Disclosure1General2
2026-04-1914
Active Exploitation7Disclosure1General1Patch4PoC1
2026-04-2018
Active Exploitation13Disclosure3General1Patch1
2026-04-2111
Active Exploitation8Disclosure1Patch2
2026-04-225
Active Exploitation5
2026-04-234
Active Exploitation3Patch1
2026-04-242
Active Exploitation2
2026-04-252
Active Exploitation2
2026-04-262
Active Exploitation1Patch1
2026-04-271
Disclosure1
2026-04-284
Active Exploitation1Disclosure2General1
2026-04-291
Patch1
2026-04-304
Active Exploitation1Disclosure1Patch2
2026-05-013
Active Exploitation1General2
2026-05-021
Active Exploitation1
2026-05-062
General2
2026-05-071
Active Exploitation1
2026-05-141
Active Exploitation1
2026-05-153
Active Exploitation2PoC1
2026-05-161
Active Exploitation1
2026-05-191
General1
2026-05-213
Active Exploitation3
2026-05-251
Disclosure1
2026-06-061
Exploit1
2026-06-081
Exploit1
2026-06-091
PoC1
2026-06-121
Active Exploitation1
2026-06-245
Disclosure4General1
2026-07-021
Exploit1
2026-07-031
PoC1
2026-07-042
Patch1PoC1
2026-07-311
Disclosure1
Full discourse20 posts
  • Horizon3 Attack Team@Horizon3Attack
    PoC

    We used Claude to discover CVE-2026-34197, a remote code execution vulnerability affecting the #Apache #ActiveMQ Classic web console. This is exploitable with default creds or completely unauthenticated for certain versions. https://horizon3.ai/intelligence/blogs/cve-2026-34197-activemq-rce-jolokia/

    Post summary

    CVE-2026-34197 is a remote code execution flaw in Apache ActiveMQ Classic web console, exploitable via default or unauthenticated credentials, with a blog link likely reporting PoC details.

    2133162332944.6K
    12.3K followersView on X
  • pyn3rd@pyn3rd
    Disclosure

    #CVE-2026-40466 is a bypass of CVE-2026-34197 in Apache ActiveMQ, exploiting the vm:// protocol to achieve Remote Code Execution https://t.co/078DSNWWkC

    Post summary

    The tweet discloses a new Apache ActiveMQ vulnerability (CVE-2026-40466) that bypasses the earlier CVE-2026-34197 flaw by exploiting the vm:// protocol to achieve remote code execution.

    060127612220.9K
    15.1K followersView on X
  • pyn3rd@pyn3rd
    General

    #CVE-2026-34197: Apache ActiveMQ RCE via Jolokia. Unfortunately, one less 0-day in the wild… Fortunately, I might still have another. Glad Claude Code hasn’t spotted it yet. 😁 https://t.co/v1pUAEKFTq

    Post summary

    The tweet highlights an RCE vulnerability in Apache ActiveMQ via Jolokia but does not provide evidence of exploitation, a PoC, or patch information.

    43902075216.4K
    15.1K followersView on X
  • The Hacker News@TheHackersNews
    Patch

    A 13-year-old flaw in Apache ActiveMQ can lead to RCE. CVE-2026-34197 lets attackers run OS commands via the Jolokia API. Chained with CVE-2024-32114, it becomes unauthenticated RCE on some versions. Patched in 5.19.4 and 6.2.3. 🔗 Learn more → https://thehackernews.com/2026/04/threatsday-bulletin-hybrid-p2p-botnet.html#chained-flaws-enable-stealth-rce https://t.co/8itN49FWEQ

    Post summary

    The post announces a 13‑year‑old Apache ActiveMQ vulnerability (CVE‑2026‑34197) that enables OS command execution via the Jolokia API, can be chained with CVE‑2024‑32114 for unauthenticated RCE, and notes that the issue is fixed in versions 5.19.4 and 6.2.3.

    34421443022.0K
    1.7M followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    Apache ActiveMQ Classic RCE research: CVE-2026-34197 / CVE-2026-42588 bypass chain + hardened-6.2.6 audit findings https://github.com/dinosn/apache-activemq-rce-research

    Post summary

    The post announces research on an RCE vulnerability in Apache ActiveMQ Classic, providing a GitHub link to presumably PoC code and technical details, but it does not report active exploitation or offer a patch.

    016059355.4K
    160.8K followersView on X
  • Clandestine@akaclandestine
    Exploit

    GitHub - Catherines77/ActiveMQ-EXPtools: Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588) · GitHub https://github.com/Catherines77/ActiveMQ-EXPtools

    Post summary

    The GitHub repository hosts an exploitation toolset for several ActiveMQ CVEs, providing PoC/exploit code without mentioning patches, active exploitation, or false positives.

    013051324.4K
    62.7K followersView on X
  • Crowdfense@crowdfense
    PoC

    Two bypasses chained into a fresh RCE on fully patched Apache ActiveMQ 6.2.5 (Windows, via WebDAV), found while researching CVE-2026-34197. https://www.crowdfense.com/apache-activemq-rce-bypass/

    Post summary

    Researchers uncovered a fresh RCE in fully patched Apache ActiveMQ 6.2.5 by chaining two bypasses via WebDAV and shared a proof‑of‑concept link.

    171404412.5K
    3.0K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added Apache ActiveMQ improper input validation vulnerability CVE-2026-34197 to our Known Exploited Vulnerabilities Catalog. Visit https://go.dhs.gov/Z3Q for more information. https://t.co/WCU1hYUn9R

    Post summary

    The DHS added CVE-2026-34197 to its Known Exploited Vulnerabilities Catalog, indicating that the Apache ActiveMQ improper input validation flaw is being abused in the wild, and provides a link for further details.

    42605578.2K
    299.1K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    Proof of concept for CVE-2026-34197 exploiting Apache ActiveMQ via Jolokia MBean and VM Transport. Includes command execution capabilities through a malicious Spring XML payload. https://github.com/dinosn/CVE-2026-34197

    Post summary

    A proof‑of‑concept for CVE-2026-34197 demonstrates exploitation of Apache ActiveMQ through Jolokia MBean and VM Transport, enabling command execution via a malicious Spring XML payload, with the code hosted on GitHub.

    120047193.9K
    157.2K followersView on X
  • Jacob Baines@Junior_Baines
    Active Exploitation

    Our canary network is seeing unauthenticated exploitation of Apache ActiveMQ via CVE-2024-32114 + CVE-2026-34197. CVE-2024-32114 is not on CISA KEV but we added it to VulnCheck KEV today. We see spread of CVE-2026-34197, but CVE-2024-32114 is sourcing from Digital Ocean atm.

    Post summary

    The message reports active, unauthenticated exploitation of two Apache ActiveMQ CVEs with evidence of spread and source but provides no PoC, exploit code, patch, or technical details.

    0821576.5K
    3.7K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    10 Minutes with Claude: Remote Code Execution in Apache ActiveMQ (CVE-2026-34197) https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/

    Post summary

    The tweet announces a Remote Code Execution vulnerability in Apache ActiveMQ (CVE‑2026‑34197) and links to a research disclosure page.

    04017101.3K
    157.2K followersView on X
  • The Shadowserver Foundation@Shadowserver
    General

    We are now scanning daily for CVE-2026-34197 (Apache ActiveMQ Improper Input Validation Vulnerability) which has recently been added to @CISACyber KEV. 6364 IPs seen vulnerable on 2026-04-19 based on a version check. Dashboard Tree Map view: https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&source=activemq&tag=cve-2026-34197%2B&data_set=count&scale=log&auto_update=on https://t.co/Br79Efgj7a

    Post summary

    The tweet reports scanning results for CVE‑2026‑34197, noting over 6,000 vulnerable IPs and linking to a dashboard, but provides no PoC, exploit, patch, or evidence of active exploitation.

    160942.1K
    21.9K followersView on X
  • Open Source Security mailing list@oss_security
    General

    Apache ActiveMQ CVE-2026-40466 Bypass CVE-2026-34197 via HTTP discovery second-stage URI https://www.openwall.com/lists/oss-security/2026/04/23/4 CVE-2026-41043 XSS when browsing queues https://www.openwall.com/lists/oss-security/2026/04/23/5 CVE-2026-41044 Authenticated RCE via DestinationView MBean exposed by Jolokia https://www.openwall.com/lists/oss-security/2026/04/23/6

    Post summary

    The text lists three ActiveMQ CVEs with brief technical descriptions but provides no PoC, exploit code, active exploitation evidence, or patch information.

    130111705
    4.7K followersView on X
  • Cantina 🪐@cantinasecurity
    Disclosure

    Apache's advisory for CVE-2026-34197 is a reminder that admin-plane exposure can sit in plain sight for years. One Jolokia path, one broker operation, one remote config load, and you have code execution. Full breakdown: https://cantina.review/cantina-agentic-5c8581 https://t.co/uqEzCdONVY

    Post summary

    The text announces Apache CVE‑2026‑34197 as an admin‑plane exposure that can lead to code execution via a Jolokia path, broker operation, and remote config load, but does not provide PoC, exploit code, active exploitation evidence, or patch information.

    120120818
    19.5K followersView on X
  • Dark Web Informer@DarkWebInformer
    Active Exploitation

    ‼️ CVE-2026-34197: 13-Year-Old Apache ActiveMQ RCE via Jolokia API Surfaces for In-the-Wild Attacks https://darkwebinformer.com/cve-2026-34197-13-year-old-apache-activemq-rce-via-jolokia-api-surfaces-for-in-the-wild-attacks/

    Post summary

    The post highlights that a long‑standing RCE in Apache ActiveMQ via the Jolokia API is being exploited in the wild, though it lacks details on PoCs, tools, or patches.

    001833.5K
    222.6K followersView on X
  • Elusive@ElusivePrivacy
    Active Exploitation

    Threat Digest | Apr 17, 2026 | CVE-2026-34197 — Apache ActiveMQ RCE via Jolokia API. Hidden for 13 years. Now actively exploited. CISA added it to KEV. CVSS: 8.8. No auth required via the Jolokia API endpoint. Federal agencies have a mandatory patch deadline. Everyone else should treat it the same. Patch now. This one's been sitting undetected since 2013. → CISA / The Hacker News / SecurityWeek 📡 http://t.me/VulnerabilityNews/42021

    Post summary

    CVE‑2026‑34197, a remote code execution flaw in Apache ActiveMQ’s Jolokia API, has been actively exploited for years and is on the CISA KEV list; all users should apply the patch immediately.

    61040129
    167 followersView on X
  • CodeWithSamzy@codewithsamzy
    Patch

    ⚠️ A critical vulnerability (CVE-2026-34197) has been identified in Apache ActiveMQ , present for over a decade. The issue lies in the Jolokia API, where insufficient input validation allows attackers to send crafted requests that trigger arbitrary OS command execution (RCE). When chained with CVE-2024-32114, the attack surface expands enabling unauthenticated RCE on certain configurations. Impact: • Remote command execution on the host • Full system compromise depending on privileges • No authentication required in some cases Patched in versions 5.19.4 and 6.2.3. If exposed externally, this is a high-risk target.

    Post summary

    The post announces CVE-2026-34197 causes remote OS command execution via Apache ActiveMQ’s Jolokia API, provides technical details and patch versions 5.19.4/6.2.3.

    200801.8K
    434 followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-34197: Apache ActiveMQ, Broker: Authenticated users could perform RCE via Jolokia MBeans https://www.openwall.com/lists/oss-security/2026/04/06/3 CVE-2026-33227: Apache ActiveMQ, Client, Broker, Web: Improper Limitation of a Pathname to a Restricted Directory https://www.openwall.com/lists/oss-security/2026/04/06/4

    Post summary

    The message announces two newly disclosed Apache ActiveMQ vulnerabilities, detailing an authenticated RCE via Jolokia MBeans and a path traversal flaw, with links to discussion threads for further information.

    12061951
    4.6K followersView on X
  • Caitlin Condon@catc0n
    Active Exploitation

    New KEV! Our initial access exploit dev team merged a rule (and an exploit) for this vulnerability barely 24 hours ago. That rule fired pretty dang quick, unsurprisingly — this is a patch bypass for CVE-2026-34197, which has been exploited since mid-April.

    Post summary

    CVE-2026-34197 is actively being exploited in the wild; a patch‑bypass rule and exploit were merged a day ago, and the vulnerability has been used since mid‑April.

    00081855
    3.6K followersView on X
  • Upwind Security MDR@UpwindMDR
    Active Exploitation

    🚨 Critical - Apache ActiveMQ RCE (CVE-2026-34197) Actively exploited in the wild! Improper input validation in the Jolokia API allows attackers to load malicious configs and execute arbitrary code on the broker. 👉 Update to 5.19.4 / 6.2.3 and restrict access to /api/jolokia/

    Post summary

    Apache ActiveMQ CVE-2026-34197 permits remote code execution via the Jolokia API; it is actively being exploited, and users are advised to update to 5.19.4 or 6.2.3 and limit Jolokia API access.

    10070144
    229 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheactivemq---
Appapacheactivemq_broker---

Explore more