apache Vulnerabilities and Affected Products
Vulnerabilities associated with ActiveMQ.
Products
Clear product- HTTP Server21 vulnerabilities
- OFBiz21 vulnerabilities
- Struts18 vulnerabilities
- inlong17 vulnerabilities
- Tomcat16 vulnerabilities
- airflow15 vulnerabilities
- Solr10 vulnerabilities
- traffic_server8 vulnerabilities
- ActiveMQ7 vulnerabilities
- linkis7 vulnerabilities
- cloudstack6 vulnerabilities
- cxf6 vulnerabilities
- dolphinscheduler6 vulnerabilities
- hertzbeat6 vulnerabilities
- http_server6 vulnerabilities
- pulsar6 vulnerabilities
- streampark6 vulnerabilities
- zeppelin6 vulnerabilities
- Apache HTTP Server5 vulnerabilities
- Apache Tomcat5 vulnerabilities
- kafka5 vulnerabilities
- ambari4 vulnerabilities
- Apache OFBiz4 vulnerabilities
- Apache Tika4 vulnerabilities
- camel4 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-40466HIGH | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Possible bypass of CVE-2026-34197 via HTTP discovery second-stage URIImproper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated attacker may bypass the fix in CVE-2026-34197 by adding a connector using an HTTP Discovery transport via BrokerView.addNetworkConnector or BrokerView.addConnector through Jolokia if the activemq-http module is on the classpath. A malicious HTTP endpoint can return a VM transport through the HTTP URI which will byp… | CVSS8.8v3.1 | EPSS4.78% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2026-34197HIGH | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeansImproper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker can invoke these operations with a… | CVSS8.8v3.1 | EPSS97.2% | PoCs16 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2024-32114HIGH | Apache ActiveMQ: Jolokia and REST API were not secured with default configurationIn Apache ActiveMQ 6.x, the default configuration doesn't secure the API web context (where the Jolokia JMX REST API and the Message REST API are located). It means that anyone can use these layers without any required authentication. Potentially, anyone can interact with the broker (using Jolokia JMX REST API) and/or produce/consume messages or purge/delete destinations (using the Message REST API). To mitigate, users can update the default conf/jetty.xml configuration file to add authenticati… | CVSS8.5v3.1 | EPSS7.15% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2023-46604CRITICAL | Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attackThe Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 … | CVSS10.0v3.1 | EPSS99.7% | PoCs37 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
Improper Input Validation and Missing Authentication for Critical Function in Apache ActiveMQIt was found that the Apache ActiveMQ client before 5.14.5 exposed a remote shutdown command in the ActiveMQConnection class. An attacker logged into a compromised broker could use this flaw to achieve denial of service on a connected client. | CVSS2.7v3.1 | EPSS1.97% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2018-8006MEDIUM | Apache ActiveMQ web console vulnerable to Cross-site ScriptingAn instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the queue.jsp page of Apache ActiveMQ versions 5.0.0 to 5.15.5. The root cause of this issue is improper data filtering of the QueueFilter parameter. | CVSS6.1v3.1 | EPSS57.2% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2016-3088CRITICAL | Improper Input Validation in Apache ActiveMQThe Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request. | CVSS9.8v3.1 | EPSS98.5% | PoCs11 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |