Apache ActiveMQ CVE-2026-34197 Added to CISA KEV Amid Active Exploitation
好的,我现在需要帮用户总结一篇文章的内容,控制在100个字以内。首先,我得仔细阅读文章,理解其主要内容。 文章讲的是Apache ActiveMQ Classic的一个高危安全漏洞CVE-2026-34197,CVSS评分8.8。这个漏洞被CISA加入到了已知被利用的漏洞目录中,并要求联邦机构在2026年4月30日前修复。漏洞允许攻击者通过Jolokia API执行任意代码,甚至无需认证,尤其是在某些旧版本中。受影响的版本包括5.19.4之前的和6.0.0到6.2.3之前的版本。建议升级到5.19.4或6.2.3。 用户的要求是用中文总结,不超过100字,不需要特定开头。我需要抓住关键点:漏洞名称、影响、CVSS评分、攻击方式、受影响版本和建议措施。 可能的结构是:Apache ActiveMQ Classic发现高危漏洞CVE-2026-34197(CVSS 8.8),允许攻击者通过Jolokia API执行任意代码,影响多个版本,需升级至5.19.4或6.2.3。 检查字数是否符合要求,并确保信息准确无误。 </think> Apache ActiveMQ Classic被发现高危漏洞CVE-2026-34197(CVSS 8.8),允许攻击者通过Jolokia API执行任意代码,影响多个版本,需升级至5.19.4或6.2.3以修复。 2026-4-17 03:22:0 Author: thehackernews.com(查看原文) 阅读量:9 收藏

Vulnerability / Enterprise Security

A recently disclosed high-severity security flaw in Apache ActiveMQ Classic has come under active exploitation in the wild, per the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

To that end, the agency has added the vulnerability, tracked as CVE-2026-34197 (CVSS score: 8.8), to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by April 30, 2026.

CVE-2026-34197 has been described as a case of improper input validation that could lead to code injection, effectively allowing an attacker to execute arbitrary code on susceptible installations. According to Horizon3.ai's Naveen Sunkavally, CVE-2026-34197 has been "hiding in plain sight" for 13 years. 

"An attacker can invoke a management operation through ActiveMQ's Jolokia API to trick the broker into fetching a remote configuration file and running arbitrary OS commands," Sunkavally added.

"The vulnerability requires credentials, but default credentials (admin:admin) are common in many environments. On some versions (6.0.0–6.1.1), no credentials are required at all due to another vulnerability, CVE-2024-32114, which inadvertently exposes the Jolokia API without authentication. In those versions, CVE-2026-34197 is effectively an unauthenticated RCE."

The vulnerability impacts the following versions -

  • Apache ActiveMQ Broker (org.apache.activemq:activemq-broker) before 5.19.4
  • Apache ActiveMQ Broker (org.apache.activemq:activemq-broker) 6.0.0 before 6.2.3
  • Apache ActiveMQ (org.apache.activemq:activemq-all) before 5.19.4
  • Apache ActiveMQ (org.apache.activemq:activemq-all) 6.0.0 before 6.2.3

Users are advised to upgrade to version 5.19.4 or 6.2.3, which addresses the issue. There are currently no details on how CVE-2026-34197 is being exploited in the wild, but SAFE Security, in a report published this week, revealed that threat actors are actively targeting exposed Jolokia management endpoints in Apache ActiveMQ Classic deployments.

The findings once again demonstrate that exploitation timelines continue to collapse as attackers pounce upon newly disclosed vulnerabilities at an alarmingly faster rate and breach systems before they can be patched.

Apache ActiveMQ is a popular target for attack, with flaws in the open-source message broker repeatedly exploited in various malware campaigns since 2021. In August 2025, a critical vulnerability in ActiveMQ (CVE-2023-46604, CVSS score: 10.0) was weaponized by unknown actors to drop a Linux malware called DripDropper.

"Given ActiveMQ’s role in enterprise messaging and data pipelines, exposed management interfaces present a high-impact risk, potentially enabling data exfiltration, service disruption, or lateral movement," SAFE Security said. "Organizations should audit all deployments for externally accessible Jolokia endpoints, restrict access to trusted networks, enforce strong authentication, and disable Jolokia where it is not required."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2026/04/apache-activemq-cve-2026-34197-added-to.html
如有侵权请联系:admin#unsafe.sh