Skip to content
COOEY

EXPOSURES › CVE-2026-34197

CVE-2026-34197

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-04-16 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-34197 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 rceexploited-in-wildunpatchedransomwaresupply-chain

Apache ActiveMQ exploited a code injection vulnerability (CVE-2026-34197) allowing remote code execution.

Apache ActiveMQ contained an improper input validation flaw enabling code injection, which was actively exploited in the wild as of July 2026. DIB organizations must patch immediately to prevent unauthorized access to messaging systems and potential data exfiltration, as this represents a critical supply-chain risk for systems relying on ActiveMQ.

Shame score — ActiveMQ shipped with a known, actively exploited code injection vulnerability that was not patched in a timely manner, exposing critical messaging infrastructure to ransomware and data theft.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.