Vulnerabilities · 101 days ago

Metasploit Makes ActiveMQ RCE Practical

A broker that requires login is still a live target once exploit tooling ships. Metasploit now has a module for CVE-2026-34197, so exposed Apache ActiveMQ management endpoints are no longer just a patching issue; they are a ready-made path for opportunistic exploitation.

Rapid7’s weekly update says the new module targets ActiveMQ’s Jolokia JMX-over-HTTP API, where a crafted management call makes the broker fetch attacker-controlled XML and turn it into code execution. The same release also adds a Gogs branch-name RCE module and a Windows kernel pointer enumerator, but the ActiveMQ module is the one that expands real-world reach.

For operators of Internet-reachable or weakly protected brokers, the shift is that an authenticated flaw can move into commodity scanning quickly once Metasploit support exists. That changes exposed management endpoints from a theoretical weakness into a practical target set.

CVE-2026-34197

NVD KEV

Known exploited · CISA KEV

CVSS 8.8 HIGH: improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ… EPSS 98% (100th percentile).

CISA federal remediation date Apr 30 · date passed

Timeline

Sources

1 source covering this story

Entities

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-06-06

Editions

Related stories