Apache Software Foundation Apache ActiveMQ Broker Vulnerabilities
CVE security advisories and vulnerability history for Apache ActiveMQ Broker by Apache Software Foundation.
Last updated
Overview
Apache Software Foundation Apache ActiveMQ Broker has 13 published CVE records since 2026, of which 1 are in CISA's Known Exploited Vulnerabilities catalog and 2 have a known public exploit. The average CVSS base score across scored CVEs is 7.0.
This page aggregates every publicly disclosed vulnerability (CVE) affecting Apache Software Foundation Apache ActiveMQ Broker, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of Apache Software Foundation Apache ActiveMQ Broker's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
In CISA’s Known Exploited Vulnerabilities catalog
1
One of Apache Software Foundation Apache ActiveMQ Broker's CVEs is confirmed exploited in the wild.
Public exploits
2
2 of Apache Software Foundation Apache ActiveMQ Broker's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every Apache Software Foundation Apache ActiveMQ Broker version named in a CVE, then pick one to see only the CVEs that affect it.
Version ranges
- 6.0.0 <= v < 6.2.64 CVEs
- < 5.19.73 CVEs
- < 5.19.83 CVEs
- 6.0.0 <= v < 6.2.73 CVEs
- < 5.19.42 CVEs
- < 5.19.62 CVEs
- 6.0.0 <= v < 6.2.52 CVEs
- < 5.19.31 CVE
- 5.14.0 <= v < 5.19.71 CVE
- 5.19.7 <= v < 5.19.81 CVE
- 6.0.0 <= v < 6.2.21 CVE
- 6.0.0 <= v < 6.2.31 CVE
- 6.0.0 <= v < 6.2.41 CVE
- 6.2.6 <= v < 6.2.71 CVE
Fixed in
- 5.19.74 CVEs
- 5.19.84 CVEs
- 6.2.64 CVEs
- 6.2.74 CVEs
- 5.19.42 CVEs
- 5.19.62 CVEs
- 6.2.52 CVEs
- 5.19.31 CVE
- 6.2.21 CVE
- 6.2.31 CVE
- 6.2.41 CVE
13 CVEs
- High · CVSS 7.5EPSS 0.7% (47th pct)2026-06-30
- High · CVSS 7.5EPSS 0.7% (49th pct)2026-06-30
- High · CVSS 7.5EPSS 0.8% (52th pct)2026-06-30
- High · CVSS 7.5EPSS 0.6% (44th pct)2026-06-30
- High · CVSS 8.1EPSS 0.5% (42th pct)2026-06-01
- High · CVSS 8.8EPSS 0.6% (44th pct)2026-06-01
- Medium · CVSS 4.3EPSS 0.3% (26th pct)2026-06-01
- Medium · CVSS 5.9EPSS 0.3% (25th pct)2026-06-01
- Medium · CVSS 6.3EPSS 1.0% (58th pct)2026-04-24
- Medium · CVSS 6.3EPSS 4.8% (91th pct)2026-04-24
- High · CVSS 7.5EPSS 0.9% (55th pct)2026-04-10
- Medium · CVSS 4.3EPSS 0.4% (34th pct)2026-04-07
- Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
Added to CISA KEV 2026-04-16
High · CVSS 8.8EPSS 96.7% (100th pct)2026-04-07
Common weakness types
The CWE weakness categories most often found in Apache Software Foundation Apache ActiveMQ Broker CVEs. Follow any weakness for its full explanation.
- CWE-20Improper Input Validation6 CVEs
- CWE-400Uncontrolled Resource Consumption2 CVEs
- CWE-1230Exposure of Sensitive Information Through Metadata1 CVE
- CWE-789Memory Allocation with Excessive Size Value1 CVE
- CWE-862Missing Authorization1 CVE
- CWE-285Improper Authorization1 CVE
- CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1 CVE
Other Apache Software Foundation products
Browse vulnerabilities for other products by Apache Software Foundation.
Frequently asked questions
Common questions about Apache Software Foundation Apache ActiveMQ Broker vulnerabilities.
- How many CVEs does Apache Software Foundation Apache ActiveMQ Broker have?
- Apache Software Foundation Apache ActiveMQ Broker has 13 published CVE records since 2026.
- How many Apache Software Foundation Apache ActiveMQ Broker CVEs are in CISA KEV?
- Yes — 1 of Apache Software Foundation Apache ActiveMQ Broker's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
- Are there public exploits for Apache Software Foundation Apache ActiveMQ Broker vulnerabilities?
- Yes — 2 of Apache Software Foundation Apache ActiveMQ Broker's CVEs have a known public exploit.
- Which versions of Apache Software Foundation Apache ActiveMQ Broker are affected?
- 25 distinct Apache Software Foundation Apache ActiveMQ Broker versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
- What are the most common weakness types in Apache Software Foundation Apache ActiveMQ Broker CVEs?
- Apache Software Foundation Apache ActiveMQ Broker's CVEs most often map to these CWE weakness types: CWE-20 (Improper Input Validation), CWE-400 (Uncontrolled Resource Consumption), CWE-1230 (Exposure of Sensitive Information Through Metadata), CWE-789 (Memory Allocation with Excessive Size Value).
- What is the average severity of Apache Software Foundation Apache ActiveMQ Broker CVEs?
- The average CVSS base score across Apache Software Foundation Apache ActiveMQ Broker's scored CVEs is 7.0.
References
- All Apache Software Foundation vulnerabilities
- The MITRE CVE Program (opens in a new tab)
- Learn: What is a CVE?
- CWE directory: the weakness types these CVEs map to
Vulnerability data is sourced from the CVE Program; severity, KEV, and exploit signals are aggregated by RadicalNotion.AI.
Track Apache Software Foundation Apache ActiveMQ Broker vulnerabilities
Monitor new Apache Software Foundation Apache ActiveMQ Broker vulnerabilities as they are disclosed, with AI-written analysis and remediation guidance.