CVE-2026-34197
Known exploited · CISA KEV
CVSS 8.8 HIGH: improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ… EPSS 15% (97th percentile).
CISA federal remediation date Apr 30
Vulnerabilities · 162 days ago
Exposed ActiveMQ management interfaces are the real problem here. CVE-2026-34197 lets an attacker reach arbitrary command execution through Jolokia JMX-HTTP, so the standard response of treating this as a generic broker bug misses the immediate risk: any internet-facing management plane can become a remote shell.
FortiGuard says the flaw affects Apache ActiveMQ Classic and that CISA has added it to the Known Exploited Vulnerabilities catalog, which confirms active exploitation. The vendor points to fixes in ActiveMQ 5.19.4+ and 6.2.3+, and calls out the exposed web console on port 8161 and Jolokia access as the key exposure points.
The forward risk is simple. If management endpoints stay reachable from untrusted networks, patching alone does not remove the attack path until exposure is reduced and credentials and permissions are tightened.
Known exploited · CISA KEV
CVSS 8.8 HIGH: improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ… EPSS 15% (97th percentile).
CISA federal remediation date Apr 30
1 source covering this story
FortiGuard Labs Threat Signals
Threat Signal Report | FortiGuard Labs
What is the Vulnerability?CVE-2026-34197 is a high-severity remote code execution (RCE) vulnerability affecting Apache ActiveMQ Classic.
Part of the PlainSec briefing for 2026-04-21