Skip to main content

ActiveMQ vulnerabilities

2 published alerts for Apache ActiveMQ.

Actively exploited (KEV)

CVE-2026-34197

Apache ActiveMQ Improper Input Validation Vulnerability

Apache ActiveMQ is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-34197). Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection. CISA remediation due date: 2026-04-30. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-46604

Apache ActiveMQ Deserialization of Untrusted Data Vulnerability

Apache ActiveMQ is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-46604). Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath. CISA remediation due date: 2023-11-23. If you need help checking exposure, call (864) 335-9223.