Exposed Jolokia management endpoints turn long-lived ActiveMQ Classic deployments into remote code execution targets. The standard response of patching the broker misses the bigger problem: if attackers already have credentials, or if Jolokia is exposed without auth on affected 6.0.0–6.1.1 builds, they can reach arbitrary OS command execution through the management plane.
CISA added CVE-2026-34197 to KEV and set an April 30, 2026 deadline for FCEB agencies. The flaw is an improper input-validation issue in Apache ActiveMQ Classic that affects org.apache.activemq:activemq-broker and org.apache.activemq:activemq-all before 5.19.4, and 6.0.0 before 6.2.3; Apache says 5.19.4 and 6.2.3 fix it.
The risk persists in environments that left default credentials in place or exposed Jolokia for convenience. In those deployments, exploitation does not require new technique development, so legacy brokers remain a ready-made path to code execution.