Skip to content
COOEY

FAIL › dossier

ActiveMQ

PRODUCT

· dossier confidence 50%

ActiveMQ, an open-source messaging broker, has experienced significant security vulnerabilities, including remote code execution and file upload issues.

PROFILE
CategoryMessaging SoftwareWhat they doActiveMQ is an open-source message broker that enables the decoupling of distributed systems, often used for asynchronous communication.
SECURITY POSTURE

The company has faced multiple security vulnerabilities, indicating a need for continuous improvement in security practices.

Notable failures
  • CVE-2023-46604: Remote code execution through deserialization vulnerability in OpenWire protocol
  • CVE-2026-34197: Code injection vulnerability allowing remote code execution
  • CVE-2016-3088: Arbitrary file upload and execution via HTTP PUT and MOVE requests
Patterns: Repeated deserialization vulnerabilities; Code injection vulnerabilities; File upload vulnerabilities
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2023-11-02 CVE-2023-46604 critical A remote attacker could execute arbitrary shell commands on an Apache ActiveMQ broker by exploiting a deserialization vulnerability in the OpenWire protocol.
2022-02-10 CVE-2016-3088 high Apache ActiveMQ's Fileserver web app allowed remote attackers to upload and execute arbitrary files via HTTP PUT and MOVE requests.
2026-04-16 CVE-2026-34197 high Apache ActiveMQ exploited a code injection vulnerability (CVE-2026-34197) allowing remote code execution.
Open questions: How has the company addressed these vulnerabilities? · What is the current state of security in the product?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-26 03:45:31.622167+00:00