
Apache ActiveMQ CVE-2026-39304: Incorrect handling of TLSv1.3 KeyUpdate can be exploited to cause DoS via OOM https://www.openwall.com/lists/oss-security/2026/04/09/17 CVE-2026-40046: Missing fix for CVE-2025-66168: MQTT control packet remaining length field is not properly validated https://www.openwall.com/lists/oss-security/2026/04/09/18
Post summary
The post discloses two new Apache ActiveMQ CVEs, outlining a DoS flaw with TLSv1.3 KeyUpdate and a missing patch for a previously known MQTT validation issue, but provides no PoC, exploit code, or evidence of active exploitation.

