CVE-2026-34197
Known exploited · CISA KEV
CVSS 8.8 HIGH: improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ… EPSS 98% (100th percentile).
CISA federal remediation date Apr 30
Vulnerabilities & Exploits
Exposed Jolokia management endpoints turn long-lived ActiveMQ Classic deployments into remote code execution targets. The standard response of patching the broker misses the bigger problem: if attackers already have credentials, or if Jolokia is exposed without auth on affected 6.0.0–6.1.1 builds, they can reach arbitrary OS command execution through the management plane.
CISA added CVE-2026-34197 to KEV and set an April 30, 2026 deadline for FCEB agencies. The flaw is an improper input-validation issue in Apache ActiveMQ Classic that affects org.apache.activemq:activemq-broker and org.apache.activemq:activemq-all before 5.19.4, and 6.0.0 before 6.2.3; Apache says 5.19.4 and 6.2.3 fix it.
The risk persists in environments that left default credentials in place or exposed Jolokia for convenience. In those deployments, exploitation does not require new technique development, so legacy brokers remain a ready-made path to code execution.
4 sources · Apr 22
Government advisory confirms CVE-2026-34197 in the KEV Catalog, while security media and threat researchers report active exploitation via the Jolokia API and note chaining with CVE-2024-32114 can produce unauthenticated RCE on some versions.
Known exploited · CISA KEV
CVSS 8.8 HIGH: improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ… EPSS 98% (100th percentile).
CISA federal remediation date Apr 30
CSO Online
Thousands of Apache ActiveMQ instances still unpatched, weeks after an actively exploited hole discovered
Now that an attacker can use an LLM to weaponize a bug the minute it's found, taking 12 days to patch ‘is essentially a suicide note for your network,’ says an expert.
originalThe Register Security
CISA tells feds to patch 13-year-old Apache ActiveMQ bug
: Bug hiding in plain sight for over a decade lands on KEV list
originalSecurityWeek
Recent Apache ActiveMQ Vulnerability Exploited in the Wild
The remote code execution vulnerability tracked as CVE-2026-34197 came to light in early April.
originalPart of the PlainSec briefing for 2026-04-18
Every edition of this story: ActiveMQ Management Endpoints Enable Credentialed RCE