Vulnerabilità ed exploit · Attacco ad app web
Metasploit Rende Pratico l'RCE di ActiveMQ Un broker che richiede login è ancora un target attivo una volta che viene rilasciato tooling per l'exploit. Metasploit ora ha un modulo per CVE-2026-34197 , quindi gli endpoint di management Apache ActiveMQ esposti non sono più solo una questione di patching; sono un percorso già pronto per lo sfruttamento opportunistico.
1 fonte · 5 giu
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 8.8 HIGH: improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ… EPSS 15% (97º percentile).
Data di correzione federale CISA 30 apr · data superata
Cronologia Fonti 5 giu Rapid7
Metasploit Wrap-Up 05/06/2026
Weekly Metasploit Update: Apache ActiveMQ RCE, Gogs Rebase RCE, Windows Kernel Pointer Enum, and more
originale Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-06-06
Every edition of this story: Metasploit Rende Pratico l'RCE di ActiveMQ
Altro da oggi
Vulnerabilità ed exploit · Attacco ad app web
Metasploit Rende Pratico l'RCE di ActiveMQ Un broker che richiede login è ancora un target attivo una volta che viene rilasciato tooling per l'exploit. Metasploit ora ha un modulo per CVE-2026-34197 , quindi gli endpoint di management Apache ActiveMQ esposti non sono più solo una questione di patching; sono un percorso già pronto per lo sfruttamento opportunistico.
1 fonte · 5 giu
NVD KEV
Sfruttamento noto · CISA KEV
CVSS 8.8 HIGH: improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ… EPSS 15% (97º percentile).
Data di correzione federale CISA 30 apr · data superata
Cronologia Fonti 5 giu Rapid7
Metasploit Wrap-Up 05/06/2026
Weekly Metasploit Update: Apache ActiveMQ RCE, Gogs Rebase RCE, Windows Kernel Pointer Enum, and more
originale Riepilogo fornitore: Microsoft
Part of the PlainSec briefing for 2026-06-06
Every edition of this story: Metasploit Rende Pratico l'RCE di ActiveMQ
Altro da oggi