CVE security advisories and vulnerability history for activemq by apache.
63
Total CVEs
Published
3
In CISA KEV
Exploited in the wild
9
Public exploits
With known exploit
6.5
Avg CVSS
2010–2026
Last updated
Overview
apache activemq has 63 published CVE records since 2010, of which 3 are in CISA's Known Exploited Vulnerabilities catalog and 9 have a known public exploit. The average CVSS base score across scored CVEs is 6.5.
This page aggregates every publicly disclosed vulnerability (CVE) affecting apache activemq, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of apache activemq's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical2
High8
Medium19
Low1
33 additional CVEs have no CVSS severity score.
In CISA’s Known Exploited Vulnerabilities catalog
3
3 of apache activemq's CVEs are confirmed exploited in the wild.
Public exploits
9
9 of apache activemq's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every apache activemq version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about apache activemq vulnerabilities.
How many CVEs does apache activemq have?
apache activemq has 63 published CVE records since 2010.
How many apache activemq CVEs are in CISA KEV?
Yes — 3 of apache activemq's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
Are there public exploits for apache activemq vulnerabilities?
Yes — 9 of apache activemq's CVEs have a known public exploit.
Which versions of apache activemq are affected?
1,139 distinct apache activemq versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in apache activemq CVEs?
apache activemq's CVEs most often map to these CWE weakness types: CWE-502 (Deserialization of Untrusted Data), CWE-20 (Improper Input Validation), CWE-434 (Unrestricted Upload of File with Dangerous Type), CWE-94 (Improper Control of Generation of Code ('Code Injection')).
How many critical apache activemq vulnerabilities are there?
apache activemq has 2 critical and 8 high-severity CVEs.
What is the average severity of apache activemq CVEs?
The average CVSS base score across apache activemq's scored CVEs is 6.5.