CVE-2026-34197
Known exploited · CISA KEV
CVSS 8.8 HIGH: improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ… EPSS 98% (100th percentile).
CISA federal remediation date Apr 30
Vulnerabilities · 146 days ago
Exposed Jolokia management endpoints turn long-lived ActiveMQ Classic deployments into remote code execution targets. The standard response of patching the broker misses the bigger problem: if attackers already have credentials, or if Jolokia is exposed without auth on affected 6.0.0–6.1.1 builds, they can reach arbitrary OS command execution through the management plane.
CISA added CVE-2026-34197 to KEV and set an April 30, 2026 deadline for FCEB agencies. The flaw is an improper input-validation issue in Apache ActiveMQ Classic that affects org.apache.activemq:activemq-broker and org.apache.activemq:activemq-all before 5.19.4, and 6.0.0 before 6.2.3; Apache says 5.19.4 and 6.2.3 fix it.
The risk persists in environments that left default credentials in place or exposed Jolokia for convenience. In those deployments, exploitation does not require new technique development, so legacy brokers remain a ready-made path to code execution.
Known exploited · CISA KEV
CVSS 8.8 HIGH: improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ… EPSS 98% (100th percentile).
CISA federal remediation date Apr 30
4 sources covering this story
Now that an attacker can use an LLM to weaponize a bug the minute it's found, taking 12 days to patch ‘is essentially a suicide note for your network,’ says an expert.
CISA tells feds to patch 13-year-old Apache ActiveMQ bug
: Bug hiding in plain sight for over a decade lands on KEV list
Recent Apache ActiveMQ Vulnerability Exploited in the Wild
The remote code execution vulnerability tracked as CVE-2026-34197 came to light in early April.
CISA flags Apache ActiveMQ flaw as actively exploited in attacks
CISA warned that attackers are now exploiting a high-severity Apache ActiveMQ vulnerability, which was patched earlier this month after going undetected for 13 years.
Part of the PlainSec briefing for 2026-04-18