CVE-2026-41044Disclosure(apache / activemq)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache activemq systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All. An authenticated attacker can use the admin web console page to construct a malicious broker name that bypasses name validation to include an xbean binding that can be later used by a VM transport to load a remote Spring XML application. The attacker can then use the DestinationView mbean to send a message to trigger a VM transport creation that will reference this malicious broker name which can lead to loading the malicious Spring XML context file. Because Spring's ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker's JVM through bean factory methods such as Runtime.exec(). This issue affects Apache ActiveMQ: before 5.19.6, from 6.0.0 before 6.2.5; Apache ActiveMQ Broker: before 5.19.6, from 6.0.0 before 6.2.5; Apache ActiveMQ All: before 5.19.6, from 6.0.0 before 6.2.5. Users are recommended to upgrade to version 6.2.5 or 5.19.6, which fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • activemq
  • activemq_broker

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-04-24); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
activemqactivemq_broker

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-04-23: 1Mentions · 2026-04-24: 2Mentions · 2026-04-25: 1Mentions · 2026-04-26: 1Mentions · 2026-04-28: 1Patch / Workaround · 2026-04-24: 1Patch / Workaround · 2026-04-26: 1Technical Details · 2026-04-24: 2Technical Details · 2026-04-25: 1Technical Details · 2026-04-26: 1Technical Details · 2026-04-28: 104-2304-2404-2504-2604-28
Signal classification4 categories
Disclosure
233.3%
Patch
233.3%
General
116.7%
Discl
116.7%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-04-231
General1
2026-04-242
Disclosure1Patch1
2026-04-251
Discl1
2026-04-261
Patch1
2026-04-281
Disclosure1
Full discourse6 posts
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-41044 + CVE-2026-40466: Apache ActiveMQ Classic authenticated RCE/code injection flaws may impact exposed broker or admin-console deployments. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJBUEFDSEUtQWN0aXZlTVEi 🎯3M+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="APACHE-ActiveMQ" 🔖Refer: https://activemq.apache.org/security-advisories.data/CVE-2026-41044-announcement.txt #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The tweet announces authenticated RCE/code injection vulnerabilities (CVE-2026-41044 & CVE-2026-40466) in Apache ActiveMQ Classic, references FOFA search results, and points to a vendor advisory for more details.

    01402762.6K
    14.4K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    Apache ActiveMQ CVE-2026-40466 Bypass CVE-2026-34197 via HTTP discovery second-stage URI https://www.openwall.com/lists/oss-security/2026/04/23/4 CVE-2026-41043 XSS when browsing queues https://www.openwall.com/lists/oss-security/2026/04/23/5 CVE-2026-41044 Authenticated RCE via DestinationView MBean exposed by Jolokia https://www.openwall.com/lists/oss-security/2026/04/23/6

    Post summary

    The text announces three new CVEs affecting Apache ActiveMQ, detailing their types (bypass, XSS, authenticated RCE) and providing reference links, but it does not include PoC, exploit code, patches, or evidence of active exploitation.

    130111705
    4.7K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Critical RCE and XSS vulnerabilities hit Apache ActiveMQ (CVE-2026-41044, 40466). Authenticated attackers can hijack the JVM. Update to 5.19.6 or 6.2.5 now. #ActiveMQ #CyberSecurity #RCE #InfoSec #PatchNow #JavaSecurity #Middleware #CVE https://securityonline.info/activemq-rce-jolokia-spring-vulnerabilities-patch-guide/ https://t.co/MVFy6CROaB

    Post summary

    The post alerts to critical RCE/XSS in Apache ActiveMQ and urges users to apply the latest patches (5.19.6 or 6.2.5).

    13063716
    12.5K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 High - Apache ActiveMQ authenticated RCE (CVE-2026-40466, CVE-2026-41044) CVE-2026-40466 - Authenticated RCE via Jolokia by loading remote Spring XML through HTTP Discovery transport. CVE-2026-41044 - Authenticated RCE via malicious broker names in the admin console triggering XBean bindings leading to code execution. 👉 Upgrade: 5.19.6 / 6.2.5

    Post summary

    Two authenticated RCE CVEs in Apache ActiveMQ are disclosed with technical details; the advisory recommends patching to 5.19.6 or 6.2.5.

    00040115
    44 followersView on X
  • CVE@CVEnew
    Discl

    CVE-2026-41044 Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All. A… https://www.cve.org/CVERecord?id=CVE-2026-41044

    Post summary

    The post announces CVE‑2026‑41044, marking a code‑injection flaw due to improper input validation in Apache ActiveMQ, but provides no further details on PoC, exploitation, or remediation.

    0000088
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-41044 CVE-2026-41044 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41044

    Post summary

    Only the CVE ID and a reference link are provided, with no further technical or exploitation details.

    0000062
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheactivemq---
Appapacheactivemq_broker---

Explore more