VendorsApacheactivemq_brokerall versions
Vulnerabilities

Apache Activemq Broker

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2026-34197
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
Published 2026-04-07 · Analyzed
8.8KEVEPSS 0.983
CVE-2026-40466
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Possible bypass of CVE-2026-34197 via HTTP discovery second-stage URI
Published 2026-04-24 · Modified
8.8EPSS 0.048
CVE-2026-41044
Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All: Authenticated user can perform RCE via DestinationView MBean exposed by Jolokia
Published 2026-04-24 · Modified
8.8EPSS 0.010
CVE-2026-45505
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia `addNetworkConnector` Discovery Wrapper Bypass
Published 2026-06-01 · Analyzed
8.8EPSS 0.006
CVE-2026-42588
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Remote Code Execution via Jolokia addNetworkConnector
Published 2026-06-01 · Analyzed
8.1EPSS 0.007
CVE-2026-39304
Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incorrect handling of TLSv1.3 KeyUpdate can be exploited to cause DoS via OOM
Published 2026-04-10 · Modified
7.5EPSS 0.009
CVE-2026-53917
Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker: Unbounded memory allocation in OpenWire property unmarshalling
Published 2026-06-30 · Analyzed
7.5EPSS 0.007
CVE-2026-50750
Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire DoS following fix for CVE-2026-49270
Published 2026-06-30 · Analyzed
7.5EPSS 0.007
CVE-2026-74761
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscription clientId
Published 2026-09-09 · Analyzed
7.5EPSS 0.006
CVE-2026-49434
Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: LdapNetworkConnector instantiates denied transports and a remote-properties broker
Published 2026-06-30 · Analyzed
7.5EPSS 0.006
CVE-2026-54475
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Temporary destination ownership takeover
Published 2026-06-30 · Analyzed
7.5EPSS 0.006
CVE-2026-61487
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authorization bypass via temporary composite destinations
Published 2026-07-28 · Analyzed
6.5EPSS 0.004
CVE-2026-49270
Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Durable Subscription Disclosure via Crafted BrokerInfo (OpenWire)
Published 2026-06-01 · Analyzed
5.9EPSS 0.004
CVE-2026-33227
Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ: Improper Limitation of a Pathname to a Restricted Classpath Directory
Published 2026-04-07 · Analyzed
4.3EPSS 0.004
CVE-2026-46605
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incomplete authorization during destination removal
Published 2026-06-01 · Analyzed
4.3EPSS 0.003