Vulnerabilità ed exploit

ActiveMQ Brokers Exposed to Active Exploitation at Scale

Apache ActiveMQ brokers are not just vulnerable here. They are already a live target, and patching only closes the door for future attacks. The standard response misses the bigger problem: authenticated code injection on a message broker can turn a trusted internal service into an execution point inside the environment.

Shadowserver found more than 6,400 exposed Apache ActiveMQ servers vulnerable to CVE-2026-34197. Apache patched ActiveMQ Classic in 6.2.3 and 5.19.4, and CISA said the flaw is actively exploited and ordered federal civilian agencies to secure affected systems by April 30.

The risk persists anywhere ActiveMQ is exposed and unpatched. Once attackers have authenticated access, they can use the flaw to run arbitrary code, so the issue is not limited to initial compromise but to what a broker can do inside a network after it is trusted.

1 fonte · 21 apr

CVE-2026-34197

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 8.8 HIGH: improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ… EPSS 15% (97º percentile).

Data di correzione federale CISA 30 apr

Cronologia

Fonti

Part of the PlainSec briefing for 2026-04-21

Every edition of this story: ActiveMQ Brokers Exposed to Active Exploitation at Scale

Altro da oggi