• News/
  • https://www.theregister.com/2026/04/17/cisa_tells_feds_to_patch/

CISA tells feds to patch 13-year-old Apache ActiveMQ bug under active attack

The Register
·
Carly Page
·
Published Apr 17, 2026
·
Updated

CISA is sounding the alarm on a newly-exploited Apache ActiveMQ bug, ordering federal agencies to patch within two weeks as attackers circle a flaw that's been quietly lurking for more than a decade. The US cybersecurity agency added the bug, tracked as CVE-2026-34197, to its Known Exploited Vulnerabilities (KEV) catalog on Thursday, triggering a Binding Operational Directive (BOD) 22-01 deadline that gives Federal Civilian Executive Branch agencies until April 30 to fix their systems or get ready to explain why not. The bug sits in Apache ActiveMQ, an open source message broker used to shuttle data between applications and services, and allows an authenticated user to execute arbitrary code via the broker's Jolokia management API – effectively turning a messaging workhorse into a remote command runner. It was disclosed just over a week ago by Horizon3 researcher Naveen Sunkavally, who used Anthropic's Claude AI assistant to help dig it out. According to Horizon3, the issue has been sitting in the codebase for 13 years, unnoticed until now. Patches are available in ActiveMQ versions 5.19.5 and 6.2.3. "CVE-2026-34197 is a remote code execution vulnerability in Apache ActiveMQ Classic that has been hiding in plain sight for 13 years," Sunkavally said. "An attacker can invoke a management operation through ActiveMQ's Jolokia API to trick the broker into fetching a remote configuration file and running arbitrary OS commands." While the bug technically requires authentication, Hor...

Read full article

Affected Software

3 affected components
Apache ActiveMQ Classic=5.19.5
Apache ActiveMQ=6.2.3
Apache ActiveMQ>=6.0.0<=6.1.1

Frequently Asked Questions

1

What vulnerability is highlighted in the article?

The article discusses a critical vulnerability in Apache ActiveMQ that has been unpatched for over 13 years.

2

What actions has CISA taken regarding this vulnerability?

CISA has ordered federal agencies to patch the Apache ActiveMQ vulnerability within a two-week timeframe.

3

What products are affected by this Apache ActiveMQ bug?

The affected products include Apache ActiveMQ Classic version 5.19.5 and Apache ActiveMQ versions between 6.0.0 and 6.2.3.

4

Why is the flaw in Apache ActiveMQ considered urgent?

The vulnerability is under active exploitation, making immediate action necessary to protect federal systems.

5

What is the potential impact of ignoring this patch recommendation?

Ignoring the patch could lead to successful cyber attacks exploiting the long-standing vulnerability in Apache ActiveMQ.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203