Critical code execution flaw found in Apache ActiveMQ Classic

A critical remote code execution vulnerability, CVE-2026-34197, has been identified in Apache ActiveMQ Classic. The flaw sits in the Jolokia API and allows an attacker to execute arbitrary commands. Exploitation normally requires authentication, but related issues such as CVE-2024-32114 can expose the API publicly, and default credentials remain a common risk. The recommendation is to upgrade immediately to Apache ActiveMQ 5.19.4 or 6.2.3 and disable default credentials.

What this means for your organisation

Message queues are the infrastructure nobody sees and everybody depends on. They were often set up long ago, by someone who has since moved on, and they sit in the middle of the data flow between systems. An attacker able to run commands there stands in a position with both access and visibility. The authentication requirement helps little if the installation still uses the vendor's default credentials.

Berigo recommends

  • Upgrade to ActiveMQ 5.19.4 or 6.2.3.
  • Check whether the Jolokia API is reachable from the internet, and close it if it is.
  • Replace default credentials in every ActiveMQ installation, including test and development environments.
  • Add message queues and other middleware to your system inventory, so the next advisory reaches an owner.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch