CVE-2026-53917
- EPSS 1.18%
- Veröffentlicht 30.06.2026 09:49:17
- Zuletzt bearbeitet 02.07.2026 18:41:55
Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker. An authenticated user can cause a broker DoS by sending a crafted OpenWire Message with a large encode...
CVE-2026-54475
- EPSS 0.9%
- Veröffentlicht 30.06.2026 09:48:28
- Zuletzt bearbeitet 02.07.2026 18:41:49
Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic temporary destinations are expected to be isolated to the connection that created them. The isolation can be broken as this ...
CVE-2026-49270
- EPSS 0.37%
- Veröffentlicht 01.06.2026 09:16:20
- Zuletzt bearbeitet 22.07.2026 07:10:00
Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connector with syncDurableSubs set to true, are vulnerable to an unauthentic...
CVE-2026-49157
- EPSS 0.44%
- Veröffentlicht 01.06.2026 09:16:20
- Zuletzt bearbeitet 22.07.2026 07:10:00
Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin (low-privilege) web-login accounts access to Jo...
CVE-2026-46605
- EPSS 0.35%
- Veröffentlicht 01.06.2026 09:16:19
- Zuletzt bearbeitet 22.07.2026 07:10:00
Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions. This issue affects Apache ActiveMQ Broker: before 5.19.7, from 6.0.0 befo...
CVE-2026-45505
- EPSS 0.6%
- Veröffentlicht 01.06.2026 09:16:19
- Zuletzt bearbeitet 21.07.2026 19:10:00
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Non-parenthesized discovery wrappers such as `masterslave:vm://...,...` and `static:...
CVE-2026-42588
- EPSS 0.57%
- Veröffentlicht 01.06.2026 09:16:19
- Zuletzt bearbeitet 22.07.2026 07:10:00
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the w...
CVE-2026-42253
- EPSS 1.11%
- Veröffentlicht 01.06.2026 09:16:18
- Zuletzt bearbeitet 22.07.2026 07:10:00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. The MessageServlet in the ActiveMQ web console API copies every JMS message property into an HTTP response he...
CVE-2026-41044
- EPSS 0.98%
- Veröffentlicht 24.04.2026 10:16:53
- Zuletzt bearbeitet 15.07.2026 02:21:12
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All. An authenticated attacker can use the admin web console page to construct a malicious...
CVE-2026-41043
- EPSS 0.56%
- Veröffentlicht 24.04.2026 10:16:23
- Zuletzt bearbeitet 27.04.2026 14:49:24
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. An authenticated attacker can show malicious content when browsing queues in the web console by overriding the conte...