CVE-2026-40466Disclosure(apache / activemq)

HIGHCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch apache activemq systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated attacker may bypass the fix in CVE-2026-34197 by adding a connector using an HTTP Discovery transport via BrokerView.addNetworkConnector or BrokerView.addConnector through Jolokia if the activemq-http module is on the classpath. A malicious HTTP endpoint can return a VM transport through the HTTP URI which will bypass the validation added in CVE-2026-34197. The attacker can then use the VM transport's brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. Because Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec(). This issue affects Apache ActiveMQ Broker: before 5.19.6, from 6.0.0 before 6.2.5; Apache ActiveMQ All: before 5.19.6, from 6.0.0 before 6.2.5; Apache ActiveMQ: before 5.19.6, from 6.0.0 before 6.2.5. Users are recommended to upgrade to version 5.19.6 or 6.2.5, which fixes the issue.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-94

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • activemq
  • activemq_broker

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 15 mentions across 13 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 12 signals
  • Disclosure: 10 classified signals
  • General: 1 classified signal
  • Peaked 8d ago at 2 mentions (2026-04-28); latest day: 1
  • 15 total mentions across 13 days

Affected systems

Vendors
Products
activemqactivemq_broker

Deep dive

Activity timeline15 mentions / 13d
01122Mentions · 2026-04-23: 1Mentions · 2026-04-24: 1Mentions · 2026-04-25: 1Mentions · 2026-04-26: 1Mentions · 2026-04-28: 2Mentions · 2026-05-04: 1Mentions · 2026-05-07: 1Mentions · 2026-05-11: 1Mentions · 2026-05-13: 1Mentions · 2026-05-14: 2Mentions · 2026-05-16: 1Mentions · 2026-05-21: 1Mentions · 2026-06-08: 1PoC Mentioned / Linked · 2026-05-04: 1PoC Mentioned / Linked · 2026-05-14: 1PoC Mentioned / Linked · 2026-05-21: 1PoC Mentioned / Linked · 2026-06-08: 1Exploit Tool / Code · 2026-06-08: 1Active Exploitation · 2026-05-07: 1Patch / Workaround · 2026-04-26: 1Patch / Workaround · 2026-05-13: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-25: 1Technical Details · 2026-04-26: 1Technical Details · 2026-04-28: 2Technical Details · 2026-05-04: 1Technical Details · 2026-05-07: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-14: 2Technical Details · 2026-05-16: 1Technical Details · 2026-05-21: 104-2304-2404-2504-2604-2805-0405-0705-1105-1305-1405-1605-2106-08
Signal classification6 categories
Disclosure
1066.7%
General
16.7%
Active Exploitation
16.7%
Patch
16.7%
PoC
16.7%
Exploit
16.7%
Referenced assets17 URLs
Classification over time
DateTotalLabels
2026-04-231
General1
2026-04-241
Disclosure1
2026-04-251
Disclosure1
2026-04-261
Disclosure1
2026-04-282
Disclosure2
2026-05-041
Disclosure1
2026-05-071
Active Exploitation1
2026-05-111
Disclosure1
2026-05-131
Patch1
2026-05-142
Disclosure2
2026-05-161
Disclosure1
2026-05-211
PoC1
2026-06-081
Exploit1
Full discourse15 posts
  • pyn3rd@pyn3rd
    Disclosure

    #CVE-2026-40466 is a bypass of CVE-2026-34197 in Apache ActiveMQ, exploiting the vm:// protocol to achieve Remote Code Execution https://t.co/078DSNWWkC

    Post summary

    The tweet announces CVE‑2026‑40466 as a bypass of CVE‑2026‑34197 in Apache ActiveMQ, leveraging the vm:// protocol to enable remote code execution.

    060127612220.9K
    15.1K followersView on X
  • Clandestine@akaclandestine
    Exploit

    GitHub - Catherines77/ActiveMQ-EXPtools: Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588) · GitHub https://github.com/Catherines77/ActiveMQ-EXPtools

    Post summary

    A GitHub repository named ActiveMQ-EXPtools provides exploitation tools for multiple ActiveMQ CVEs, indicating the availability of exploit code but no evidence of active in‑the‑wild attacks.

    013051324.4K
    62.7K followersView on X
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-41044 + CVE-2026-40466: Apache ActiveMQ Classic authenticated RCE/code injection flaws may impact exposed broker or admin-console deployments. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJBUEFDSEUtQWN0aXZlTVEi 🎯3M+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="APACHE-ActiveMQ" 🔖Refer: https://activemq.apache.org/security-advisories.data/CVE-2026-41044-announcement.txt #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    Apache ActiveMQ Classic has newly disclosed authenticated RCE/code injection vulnerabilities (CVE-2026-41044 and CVE-2026-40466), with a link to the official advisory, but no PoC, exploit, or active exploitation is reported.

    01402762.6K
    14.4K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    Apache ActiveMQ CVE-2026-40466 Bypass CVE-2026-34197 via HTTP discovery second-stage URI https://www.openwall.com/lists/oss-security/2026/04/23/4 CVE-2026-41043 XSS when browsing queues https://www.openwall.com/lists/oss-security/2026/04/23/5 CVE-2026-41044 Authenticated RCE via DestinationView MBean exposed by Jolokia https://www.openwall.com/lists/oss-security/2026/04/23/6

    Post summary

    Openwall presents a list of new Apache ActiveMQ vulnerabilities (CVE-2026-40466, CVE-2026-41043, CVE-2026-41044) with brief technical descriptions but no patched or exploit details.

    130111705
    4.7K followersView on X
  • Jacob Baines@Junior_Baines
    Active Exploitation

    We, @VulnCheckAI, see CVE-2026-40466 being exploited in the wild, right now. Affecting Apache ActiveMQ, results in authenticated RCE with attackers using default credentials. 2,700+ exposed instances on Shodan.

    Post summary

    The post reports that CVE-2026-40466, an authenticated RCE in Apache ActiveMQ, is actively exploited in the wild with default credentials, affecting thousands of exposed instances.

    031622.2K
    3.7K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-40466 - high 🚨 Apache ActiveMQ - Remote Code Execution via HTTP Discovery Transport Bypass > Apache ActiveMQ before 5.19.6 and 6.0.0 through 6.2.4 is vulnerable to remote code ex... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-40466 @pdnuclei #NucleiTemp...

    Post summary

    The post announces CVE-2026-40466 as a Remote Code Execution flaw in Apache ActiveMQ versions before 5.19.6 and 6.0.0–6.2.4, and links to a library that presumably contains further details.

    00026233
    973 followersView on X
  • ET Labs@ET_Labs
    Disclosure

    29 new OPEN, 31 new PRO (29 + 2) Apache ActiveMQ (CVE-2026-40466), OpenAM (CVE-2026-33439), HumanitarianBait InfoStealer, Italiano Stealerano, Lumma Stealer, MagicG Stealer, TA569, LandUpdate808, ZPHP https://community.emergingthreats.net/t/ruleset-update-summary-2026-05-11-v11190/3313 https://t.co/yq1Mc1I183

    Post summary

    The post provides a brief ruleset update listing two new CVEs for Apache ActiveMQ and OpenAM, but offers no detailed exploitation, patch or technical information.

    03020292
    5.7K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 High - Apache ActiveMQ authenticated RCE (CVE-2026-40466, CVE-2026-41044) CVE-2026-40466 - Authenticated RCE via Jolokia by loading remote Spring XML through HTTP Discovery transport. CVE-2026-41044 - Authenticated RCE via malicious broker names in the admin console triggering XBean bindings leading to code execution. 👉 Upgrade: 5.19.6 / 6.2.5

    Post summary

    The advisory announces two authenticated RCE CVEs in Apache ActiveMQ, outlines how they are exploited, and recommends upgrading to patched versions 5.19.6 or 6.2.5.

    00040115
    44 followersView on X
  • Cloud Virtues@CloudVirtues
    Disclosure

    CVE-2026-40466 - Remote Code Execution vulnerability in Apache ActiveMQ https://dy.si/15ZLM https://t.co/FZIC20hq9M

    Post summary

    CVE-2026-40466 is disclosed as an RCE flaw in Apache ActiveMQ, with links to more details but no PoC, exploit code, patch, or active exploitation noted.

    0002044
    12 followersView on X
  • Dr. Siraj Dokadia@SirajD_Official
    PoC

    CVE-2026-40466 - Remote Code Execution vulnerability in Apache ActiveMQ https://dy.si/wLkDuY2 https://t.co/KxEYl0UsPu

    Post summary

    The tweet announces CVE-2026-40466, a Remote Code Execution vulnerability in Apache ActiveMQ, and provides links that likely contain a Proof‑of‑Concept. No evidence of active exploitation, patch availability, or false positive claims is given.

    0001042
    17 followersView on X
  • Threat Intelligence@threatintel
    Patch

    #ThreatProtection #CVE-2026-40466 - Apache ActiveMQ #RCE #vulnerability, read more about Symantec's protection: https://www.broadcom.com/support/security-center/protection-bulletin/cve-2026-40466-remote-code-execution-vulnerability-in-apache-activemq

    Post summary

    The tweet promotes Symantec’s protection bulletin for CVE‑2026‑40466, emphasizing a remote code execution vulnerability in Apache ActiveMQ and the availability of corporate mitigation steps.

    010001.1K
    115.1K followersView on X
  • Rahul R Verma@RahulRVerma
    Disclosure

    CVE-2026-40466 - Remote Code Execution vulnerability in Apache ActiveMQ https://dy.si/KvEL9W https://t.co/b2xze5IOtV

    Post summary

    The tweet announces CVE-2026-40466 as a Remote Code Execution flaw in Apache ActiveMQ, links to external content potentially containing a PoC, but provides no details on patches, active exploitation, or specific exploit code.

    0000040
    65 followersView on X
  • Guru@Guru0791
    Disclosure

    CVE-2026-40466 - Remote Code Execution vulnerability in Apache ActiveMQ https://dy.si/ZDy9G https://t.co/sjWPrQFgJP

    Post summary

    The tweet announces CVE-2026-40466, a Remote‑Code‑Execution flaw in Apache ActiveMQ, and links to further details.

    0000031
    6 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40466 Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. … https://www.cve.org/CVERecord?id=CVE-2026-40466

    Post summary

    The text announces CVE-2026-40466, a code injection flaw in Apache ActiveMQ, describing its technical nature but providing no details about exploitation, PoC, patches, or active attacks.

    00000116
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40466 CVE-2026-40466 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40466 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The post merely references CVE-2026-40466 and provides a link to a vulnerability details page, offering no further information on exploits, patches, or technical aspects.

    00000126
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheactivemq---
Appapacheactivemq_broker---

Explore more