VulnerabilitiesApr 17, 2026
‼️ CVE-2026-34197: 13-Year-Old Apache ActiveMQ RCE via Jolokia API Surfaces for In-the-Wild Attac...
CVE-2026-34197: 13-year-old Apache ActiveMQ RCE via Jolokia API exploited in wild attacks.
Vendor Watch
Run Apache ActiveMQ?
Get an email when a reviewed story names Apache ActiveMQ, usually within the hour.
Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch worksPrivacy
Summary
A critical remote code execution vulnerability in Apache ActiveMQ's Jolokia API (CVE-2026-34197) has surfaced in active, in-the-wild exploitation. The vulnerability, reportedly present for 13 years, allows unauthenticated attackers to execute arbitrary commands on affected systems. This disclosure highlights a significant risk to organizations running legacy or unpatched ActiveMQ instances.
Indicators of Compromise
- cve — CVE-2026-34197
Entities
Apache ActiveMQ (product)Jolokia API (technology)