Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Recent Apache ActiveMQ Vulnerability Exploited in the Wild

The remote code execution vulnerability tracked as CVE-2026-34197 came to light in early April.

Apache vulnerability

Organizations are warned that a recently patched vulnerability affecting Apache ActiveMQ Classic is being exploited in the wild.

The flaw is tracked as CVE-2026-34197 and it came to light roughly 10 days ago, after it lurked in the software’s code for 13 years. It has been patched with the release of versions 5.19.5 and 6.2.3.

Apache ActiveMQ is an open source, multi-protocol message broker that enables reliable, asynchronous communication between applications. 

CVE-2026-34197 is related to the Jolokia API and can allow an authenticated attacker to execute arbitrary code.

Horizon3, whose researchers discovered the vulnerability and published details on April 7, pointed out that while exploitation of CVE-2026-34197 requires authentication, many Apache ActiveMQ instances are protected by widely-known default credentials.

In addition, CVE-2026-34197 can be chained with an older vulnerability tracked as CVE-2024-32114 to achieve unauthenticated remote code execution.

Advertisement. Scroll to continue reading.

The cybersecurity agency CISA added CVE-2026-34197 to its Known Exploited Vulnerabilities (KEV) catalog on Thursday, instructing federal agencies to patch it by April 30.

No details appear to be publicly available about the attacks exploiting the vulnerability. However, Fortinet has seen dozens of exploitation attempts in the past week. 

SecurityWeek has reached out to the cybersecurity firm for more information on the nature of these exploitation attempts.

Related: Microsoft Patches Exploited SharePoint Zero-Day and 160 Other Vulnerabilities

Related: Exploited Vulnerability Exposes Nginx Servers to Hacking

Related: Cisco Patches Critical Vulnerabilities in Webex, ISE

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

People on the Move

Anurag Jain has been appointed Senior Vice President of Engineering at CodeHunter

CTERA has appointed Tal Sarfaty as Senior Vice President of Cybersecurity.

Quantum Secure Encryption has named Michael Massing as Chief Technology Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.