CISA KEV · Known exploitedHigh

CVE-2026-34197

Apache Software Foundation Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter to load a remote Spr...

CVSS
8.8
EPSS
97.2%
99.9% percentile
CISA KEV
Listed
Published
2026.04.07
PRIORITY ASSESSMENT

Immediate review

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.

Known exploitationConfirmed by CISA KEV
Exploit probability97.2%
Technical severityCVSS 8.8

Vulnerability overview

Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport's brokerConfig parameter to load a remote Spr...

Affected product and versions

Product
Apache Software Foundation Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ
Affected versions
< 5.19.4, >= 6.0.0 < 6.2.3
Fixed versions
5.19.4, 6.2.3

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
CISA required action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Due date: 2026.04.30
  1. 1
    Identify

    Confirm that Apache Software Foundation Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-20, CWE-78, CWE-94
KEV added
2026.04.16
Ransomware use
미확인
CVE-2026-34197 — Apache Software Foundation Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ | SECUFOCUS NOW