Apache
Apache Activemq: vulnerabilidades y CVE
Apache Activemq tiene 78 vulnerabilidades publicadas, 26 de ellas en los últimos 12 meses. 13 son críticas y 3 figuran en el catálogo de explotación activa de CISA.
CVE78
Últimos 12 meses26
Críticas13
Explotadas activamente3
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-34197 | Alta (8.8) | 15% | ⚠ Explotación activa | 7 abr 2026 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/… |
| CVE-2023-46604 | Crítica (9.8) | 100% | ⚠ Explotación activa | 27 oct 2023 | The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell… |
| CVE-2016-3088 | Crítica (9.8) | 99% | ⚠ Explotación activa | 1 jun 2016 | The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-74761 | Alta (7.5) | 0.62% | — | 9 sept 2026 | Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All on all platforms. An authenticated client can spoof clientId when removing a durable topic subscription. This… |
| CVE-2026-61487 | Media (6.5) | 0.46% | — | 28 jul 2026 | Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated low-privilege user can bypass a per-destination write ACL by sending to an ActiveMQ temporary… |
| CVE-2026-59878 | Alta (7.5) | 0.78% | — | 28 jul 2026 | Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remote unauthenticated peer that can reach an exposed AMQP NIO connector can trigger denial-of-service behavior by… |
| CVE-2026-54475 | Alta (7.5) | 0.56% | — | 30 jun 2026 | Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic temporary destinations are expected to be isolated to the connection that created them. The… |
| CVE-2026-53917 | Alta (7.5) | 0.74% | — | 30 jun 2026 | Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker. An authenticated user can cause a broker DoS by sending a crafted… |
| CVE-2026-53916 | Alta (7.5) | 0.74% | — | 30 jun 2026 | Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. An unauthenticated client that opens a STOMP NIO connection can send header bytes that never… |
| CVE-2026-52760 | Media (6.1) | 0.68% | — | 30 jun 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web Console. The browse page in the web console renders a message Id directly… |
| CVE-2026-50750 | Alta (7.5) | 0.69% | — | 30 jun 2026 | Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Following the fix for CVE-2026-49270 an unauthenticated attacker can now cause broker OOM by sending an… |
| CVE-2026-50734 | Alta (7.5) | 0.74% | — | 30 jun 2026 | Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All. An unauthenticated network attacker can cause a broker DoS by sending a crafted WireFormatInfo… |
| CVE-2026-49877 | Alta (8.1) | 0.51% | — | 30 jun 2026 | Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console user by default can access /admin/* paths in the Web Console. The default Jetty settings incorrectly did not limit… |
| CVE-2026-49434 | Alta (7.5) | 0.63% | — | 30 jun 2026 | Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. An attacker that has access to publish or modify entries in LDAP that match the configured searchBase and… |
| CVE-2026-49432 | Alta (7.5) | 0.78% | — | 30 jun 2026 | Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. A remote unauthenticated peer that can reach an exposed STOMP connector can trigger denial-of-service behavior by… |
| CVE-2026-49270 | Media (5.9) | 0.51% | — | 1 jun 2026 | Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connector with syncDurableSubs set to true,… |
| CVE-2026-49157 | Alta (8.8) | 0.63% | — | 1 jun 2026 | Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin (low-privilege)… |
| CVE-2026-46605 | Media (4.3) | 0.50% | — | 1 jun 2026 | Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions. This issue affects Apache ActiveMQ Broker:… |
| CVE-2026-45505 | Alta (8.8) | 0.88% | — | 1 jun 2026 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Non-parenthesized discovery wrappers such as… |
| CVE-2026-42588 | Alta (8.1) | 0.66% | — | 1 jun 2026 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP… |
| CVE-2026-42253 | Media (6.1) | 0.68% | — | 1 jun 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. The MessageServlet in the ActiveMQ web console API copies every JMS message… |
| CVE-2026-41044 | Alta (8.8) | 1.1% | — | 24 abr 2026 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All. An authenticated attacker can use the admin web console… |
| CVE-2026-41043 | Media (6.5) | 0.72% | — | 24 abr 2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. An authenticated attacker can show malicious content when browsing queues in the web… |
| CVE-2026-40466 | Alta (8.8) | 4.1% | — | 24 abr 2026 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated attacker may bypass the fix in… |
| CVE-2026-39304 | Alta (7.5) | 1.1% | — | 10 abr 2026 | Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ. ActiveMQ NIO SSL transports do not correctly handle TLSv1.3 handshake KeyUpdates triggered by… |
| CVE-2026-40046 | Alta (7.5) | 0.61% | — | 9 abr 2026 | Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT. The fix for "CVE-2025-66168: MQTT control packet remaining length field is not properly validated" was only… |
| CVE-2026-34197 | Alta (8.8) | 15% | ⚠ Explotación activa | 7 abr 2026 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/… |
| CVE-2026-33227 | Media (4.3) | 0.68% | — | 7 abr 2026 | Improper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ. In two instances (when creating a… |
| CVE-2025-66168 | Alta (8.8) | 0.78% | — | 4 mar 2026 | Users of 6.x should upgrade to 6.2.4 or later as the fix was missed in previous 6.x releases. See the following for more details: https://activemq.apache.org/security-advisories.data/CVE-2026-40046-announcement.txt… |
| CVE-2016-15046 | Alta (8.6) | 0.93% | — | 25 jul 2025 | A client-side remote code execution vulnerability exists in Hanwha Techwin Smart Security Manager (SSM) versions 1.32 and 1.4, due to improper restrictions on the PUT method exposed by the bundled Apache ActiveMQ… |
| CVE-2025-27533 | Media (6.9) | 8.7% | — | 7 may 2025 | Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ. During unmarshalling of OpenWire commands the size value of buffers was not properly validated which could lead to excessive memory… |
| CVE-2024-8689 | Media (6) | 0.22% | — | 11 sept 2024 | A problem with the ActiveMQ integration for both Cortex XSOAR and Cortex XSIAM can result in the cleartext exposure of the configured ActiveMQ credentials in log bundles. |
| CVE-2024-32114 | Alta (8.8) | 7.1% | — | 2 may 2024 | In Apache ActiveMQ 6.x, the default configuration doesn't secure the API web context (where the Jolokia JMX REST API and the Message REST API are located). It means that anyone can use these layers without any required… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.