CRITICAL10.0CVE-2023-46604⚠ KEVApache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack from 0, < 5.15.16, >= 5.16.0, < 5.16.7, >= 5.17.0, < 5.17.6, >= 5.18.0, < 5.18.3
HIGH8.8CVE-2026-34197⚠ KEVApache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans from 0, < 5.19.4, >= 6.0.0, < 6.2.3
CRITICAL9.8Remote code execution in Apache ActiveMQ
>= 5.15.12, <= 5.15.12
HIGH8.8Apache ActiveMQ: Authenticated low-privilege Web users retain Jolokia broker-management capability by default
from 0, < 5.19.7, >= 6.0.0, < 6.2.6
HIGH8.8Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Possible bypass of CVE-2026-34197 via HTTP discovery second-stage URI
from 0, < 5.19.6, >= 6.0.0, < 6.2.5
HIGH8.8Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All: Authenticated user can perform RCE via DestinationView MBean exposed by Jolokia
from 0, < 5.19.6, >= 6.0.0, < 6.2.5
HIGH8.8Apache ActiveMQ's default configuration doesn't secure the API web context
>= 6.0.0, < 6.1.2
HIGH8.8Apache ActiveMQ: Insufficient API restrictions on Jolokia allow authenticated users to perform RCE
from 0, < 5.16.6, >= 5.17.0, < 5.17.4
HIGH8.1Apache ActiveMQ: Authenticated web users retain admin access by default in the Web Console
from 0, < 5.19.8, >= 6.0.0, < 6.2.7
HIGH7.5Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Temporary destination ownership takeover
from 0, < 5.19.8, >= 6.0.0, < 6.2.7
HIGH7.5Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker: Unbounded memory allocation in OpenWire property unmarshalling
from 0, < 5.19.8, >= 6.0.0, < 6.2.7
HIGH7.5Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in STOMP NIO codec
from 0, < 5.19.8, >= 6.0.0, < 6.2.7
HIGH7.5Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire DoS following fix for CVE-2026-49270
>= 5.19.7, < 5.19.8, >= 6.2.6, < 6.2.7
HIGH7.5Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire memory-allocation DoS during wire format negotiation
from 0, < 5.19.8, >= 6.0.0, < 6.2.7
HIGH7.5Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: LdapNetworkConnector instantiates denied transports and a remote-properties broker
from 0, < 5.19.8, >= 6.0.0, < 6.2.7
HIGH7.5Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: STOMP negative content-length enables denial of service
from 0, < 5.19.8, >= 6.0.0, < 6.2.7
HIGH7.5Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incorrect handling of TLSv1.3 KeyUpdate can be exploited to cause DoS via OOM
from 0, < 5.19.4, >= 6.0.0, < 6.2.4
HIGH7.5Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation
>= 5.16.0, < 5.16.8, >= 5.17.0, < 5.17.7, >= 5.18.0, < 5.18.7, >= 6.0.0, < 6.1.6
HIGH7.5ActiveMQ: LDAP-Authentication does not verify passwords on servers with anonymous bind
>= 5.15.0, < 5.15.14, >= 5.16.0, < 5.16.1
MEDIUM6.5Apache ActiveMQ, Apache ActiveMQ Web: ActiveMQ Web Console - XSS vulnerability when browsing queues
from 0, < 5.19.6, >= 6.0.0, < 6.2.5
MEDIUM6.1Apache ActiveMQ, Apache ActiveMQ Web Console: Stored XSS via Unescaped values in ActiveMQ Web Console
from 0, < 5.19.8, >= 6.0.0, < 6.2.7
MEDIUM6.1Apache ActiveMQ, Apache ActiveMQ Web: HTTP Response Header Injection via JMS Message Properties
from 0, < 5.19.7, >= 6.0.0, < 6.2.6
MEDIUM6.1Cross-site scripting (XSS) in Apache ActiveMQ
from 0, < 5.15.14, >= 5.16.0, < 5.16.1
MEDIUM6.1Apache ActiveMQ webconsole admin GUI is open to XSS
>= 5.0.0, <= 5.15.11
MEDIUM5.9activemq - security update
from 0, < 5.15.12
MEDIUM5.4Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT: Missing fix for CVE-2025-66168: MQTT control packet remaining length field is not properly validated
>= 6.0.0, < 6.2.4
MEDIUM5.4Apache ActiveMQ, Apache ActiveMQ All Module, Apache ActiveMQ MQTT Module: MQTT control packet remaining length field is not properly validated
from 0, < 5.19.2, >= 6.0.0, < 6.1.9, >= 6.2.0, < 6.2.1
MEDIUM4.3Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incomplete authorization during destination removal
from 0, < 5.19.7, >= 6.0.0, < 6.2.6
MEDIUM4.3Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, Apache ActiveMQ: Improper Limitation of a Pathname to a Restricted Classpath Directory
from 0, < 5.19.3, >= 6.0.0, < 6.2.2