New ActiveMQ flaw bypasses the fix for an actively exploited bug

On 24 April, Apache disclosed a new code injection vulnerability that bypasses the fix for an earlier one, CVE-2026-34197. The new issue, tracked as CVE-2026-40466, affects Apache ActiveMQ, ActiveMQ Broker and ActiveMQ All, and successful exploitation may allow code execution on vulnerable systems. There are no known reports of active exploitation of CVE-2026-40466, but the earlier flaw is reported as actively exploited and public proof-of-concept code is available.

What this means for your organisation

ActiveMQ is messaging infrastructure and usually sits between systems that are otherwise well separated. Code execution there gives an attacker a foothold that is hard to detect and easy to build on. The sharper point in this case is that a patch you have already applied does not close the hole. Organisations that recorded CVE-2026-34197 as handled need to reopen the item.

Berigo recommends

  • Map where ActiveMQ actually runs in your estate, including instances bundled inside other products.
  • Update to the version that fixes CVE-2026-40466, and do not assume last cycle's patching is sufficient.
  • Restrict access to the broker so only known systems can reach it, and remove any internet exposure.
  • Review logs for signs of exploitation of CVE-2026-34197, since that flaw has been used in practice.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch