Metasploit Makes ActiveMQ RCE Practical

A broker that requires login is still a live target once exploit tooling ships. Metasploit now has a module for CVE-2026-34197, so exposed Apache ActiveMQ management endpoints are no longer just a patching issue; they are a ready-made path for opportunistic exploitation. Rapid7’s weekly update says the new module targets ActiveMQ’s Jolokia JMX-over-HTTP API, where a crafted management call makes the broker fetch attacker-controlled XML and turn it into code execution. The same release also adds a Gogs branch-name RCE module and a Windows kernel pointer enumerator, but the ActiveMQ module is the one that expands real-world reach. For operators of Internet-reachable or weakly protected brokers, the shift is that an authenticated flaw can move into commodity scanning quickly once Metasploit support exists. That changes exposed management endpoints from a theoretical weakness into a practical target set.

Part of the PlainSec briefing for 2026-06-06

Sources