Vulnerabilities · 162 days ago

ActiveMQ Exposure Turns Jolokia Into RCE Path

Exposed ActiveMQ management interfaces are the real problem here. CVE-2026-34197 lets an attacker reach arbitrary command execution through Jolokia JMX-HTTP, so the standard response of treating this as a generic broker bug misses the immediate risk: any internet-facing management plane can become a remote shell.

FortiGuard says the flaw affects Apache ActiveMQ Classic and that CISA has added it to the Known Exploited Vulnerabilities catalog, which confirms active exploitation. The vendor points to fixes in ActiveMQ 5.19.4+ and 6.2.3+, and calls out the exposed web console on port 8161 and Jolokia access as the key exposure points.

The forward risk is simple. If management endpoints stay reachable from untrusted networks, patching alone does not remove the attack path until exposure is reduced and credentials and permissions are tightened.

CVE-2026-34197

NVD KEV

Known exploited · CISA KEV

CVSS 8.8 HIGH: improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ… EPSS 15% (97th percentile).

CISA federal remediation date Apr 30

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-04-21

Editions

Related stories