Apache ActiveMQ Vulnerability Exploited, Urgent Patching Required
A recently patched vulnerability in Apache ActiveMQ Classic, identified as CVE-2026-34197, is being actively exploited. This flaw, related to the Jolokia API, allows authenticated attackers to execute arbitrary code. Despite requiring authentication, many Apache ActiveMQ instances are vulnerable due to default credentials. The vulnerability can be combined with an older flaw, CVE-2024-32114, to achieve unauthenticated remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities catalog, urging federal agencies to patch it by April 30. Fortinet has reported numerous exploitation attempts, highlighting the urgency for organizations to update to the patched versions, 5.19.5 and 6.2.3.