https://seclists.org/oss-sec/2026/q2/756: CVE-2026-42588: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: mote Code Execution via Jolokia addNetworkConnector
Published May 31, 2026
·Updated
Affected Software
3 affected components
maven/org.apache.activemq/activemq-broker<5.19.7, >=6.0.0<6.2.6
maven/org.apache.activemq/activemq-all<5.19.7, >=6.0.0<6.2.6
maven/org.apache.activemq/apache-activemq<5.19.7, >=6.0.0<6.2.6
Frequently Asked Questions
1
What is the severity of CVE-2026-42588?
CVE-2026-42588 has been categorized with an 'important' severity level.
2
How do I fix CVE-2026-42588?
To fix CVE-2026-42588, upgrade to Apache ActiveMQ Broker version 5.19.7 or 6.2.6 and later versions of all affected packages.
3
What versions are affected by CVE-2026-42588?
CVE-2026-42588 affects versions before Apache ActiveMQ Broker 5.19.7 and 6.0.0 before 6.2.6, along with Apache ActiveMQ All versions before 5.19.7.
4
What type of vulnerability is CVE-2026-42588?
CVE-2026-42588 is a remote code execution vulnerability that can be exploited via the Jolokia addNetworkConnector.
5
Is CVE-2026-42588 specific to any particular software package?
Yes, CVE-2026-42588 specifically affects the Apache ActiveMQ Broker and Apache ActiveMQ All software packages.