<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 16:33:32 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-04928</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-04928</link>
      <description>bdu:2026-04928</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-04928</guid>
    </item>
    <item>
      <title>BIT-activemq-2026-34197 — Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans</title>
      <link>https://cve.radiocsirt.org/vuln/bit-activemq-2026-34197</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: activemq&lt;/p&gt;
&lt;p&gt;Improper Input Validation, Improper Control of Generation of Code (&amp;#39;Code Injection&amp;#39;) vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ.&lt;/p&gt;
&lt;p&gt;Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including
BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String).&lt;/p&gt;
&lt;p&gt;An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport&amp;#39;s brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext.
Because Spring&amp;#39;s ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker&amp;#39;s JVM through bean factory methods such as Runtime.exec().&lt;/p&gt;
&lt;p&gt;This issue affects Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ All: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.3.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: activemq&lt;/p&gt;
&lt;p&gt;Improper Input Validation, Improper Control of Generation of Code (&amp;#39;Code Injection&amp;#39;) vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ.&lt;/p&gt;
&lt;p&gt;Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including
BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String).&lt;/p&gt;
&lt;p&gt;An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport&amp;#39;s brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext.
Because Spring&amp;#39;s ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker&amp;#39;s JVM through bean factory methods such as Runtime.exec().&lt;/p&gt;
&lt;p&gt;This issue affects Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ All: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.3.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-activemq-2026-34197</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0667 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0667</link>
      <description>certfr-2026-avi-0667</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0667</guid>
    </item>
    <item>
      <title>cnvd-2026-17369</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2026-17369</link>
      <description>cnvd-2026-17369</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2026-17369</guid>
    </item>
    <item>
      <title>EUVD-2026-354278</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-354278</link>
      <description>EUVD-2026-354278</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-354278</guid>
    </item>
    <item>
      <title>fkie_cve-2026-34197</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34197</link>
      <description>&lt;p&gt;Improper Input Validation, Improper Control of Generation of Code (&amp;#39;Code Injection&amp;#39;) vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ.&lt;/p&gt;
&lt;p&gt;Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including
BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String).&lt;/p&gt;
&lt;p&gt;An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport&amp;#39;s brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext.
Because Spring&amp;#39;s ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker&amp;#39;s JVM through bean factory methods such as Runtime.exec().&lt;/p&gt;
&lt;p&gt;This issue affects Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ All: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.3.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Improper Input Validation, Improper Control of Generation of Code (&amp;#39;Code Injection&amp;#39;) vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ.&lt;/p&gt;
&lt;p&gt;Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including
BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String).&lt;/p&gt;
&lt;p&gt;An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport&amp;#39;s brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext.
Because Spring&amp;#39;s ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker&amp;#39;s JVM through bean factory methods such as Runtime.exec().&lt;/p&gt;
&lt;p&gt;This issue affects Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ All: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.3.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-34197</guid>
    </item>
    <item>
      <title>GHSA-rxpj-7qvf-xv32 — Authenticated Apache ActiveMQ Broker and Apache ActiveMQ users could perform RCE via Jolokia MBeans</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rxpj-7qvf-xv32</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.activemq:activemq-broker, Maven: org.apache.activemq:activemq-all&lt;/p&gt;
&lt;p&gt;Improper Input Validation, Improper Control of Generation of Code (&amp;#39;Code Injection&amp;#39;) vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ.&lt;/p&gt;
&lt;p&gt;Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including
BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String).&lt;/p&gt;
&lt;p&gt;An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport&amp;#39;s brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. 
Because Spring&amp;#39;s ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker&amp;#39;s JVM through bean factory methods such as Runtime.exec().
This issue affects Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ: .&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 5.19.5 or 6.2.3, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.activemq:activemq-broker, Maven: org.apache.activemq:activemq-all&lt;/p&gt;
&lt;p&gt;Improper Input Validation, Improper Control of Generation of Code (&amp;#39;Code Injection&amp;#39;) vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ.&lt;/p&gt;
&lt;p&gt;Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including
BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String).&lt;/p&gt;
&lt;p&gt;An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport&amp;#39;s brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. 
Because Spring&amp;#39;s ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker&amp;#39;s JVM through bean factory methods such as Runtime.exec().
This issue affects Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ: .&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 5.19.5 or 6.2.3, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rxpj-7qvf-xv32</guid>
    </item>
    <item>
      <title>OESA-2026-2124 — activemq security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2124</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: activemq&lt;/p&gt;
&lt;p&gt;The most popular and powerful open source messaging and Integration Patterns server.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;[&amp;amp;apos;Severity: low \n\nAffected versions:\n\n- Apache ActiveMQ Client (org.apache.activemq:activemq-client) before 5.19.3\n- Apache ActiveMQ Client (org.apache.activemq:activemq-client) 6.0.0 before 6.2.2\n- Apache ActiveMQ Broker (org.apache.activemq:activemq-broker) before 5.19.3\n- Apache ActiveMQ Broker (org.apache.activemq:activemq-broker) 6.0.0 before 6.2.2\n- Apache ActiveMQ (org.apache.activemq:activemq-all) before 5.19.3\n- Apache ActiveMQ (org.apache.activemq:activemq-all) 6.0.0 before 6.2.2\n- Apache ActiveMQ Web (org.apache.activemq:activemq-web) before 5.19.3\n- Apache ActiveMQ Web (org.apache.activemq:activemq-web) 6.0.0 before 6.2.2\n\nDescription:\n\nImproper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ \nBroker, Apache ActiveMQ All.\n\nIn two instances (when creating a Stomp consumer and also browsing messages in the Web console) an authenticated user \nprovided &amp;amp;quot;key&amp;amp;quot; value could be constructed to traverse the classpath due to path concatenation. As a result, the \napplication is exposed to a classpath path resource loading vulnerability that could potentially be chained together \nwith another attack to lead to exploit.This issue affects Apache ActiveMQ Client: before 5.19.3, from 6.0.0 before \n6.2.2; Apache ActiveMQ Broker: before 5.19.3, from 6.0.0 before 6.2.2; Apache Activ…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: activemq&lt;/p&gt;
&lt;p&gt;The most popular and powerful open source messaging and Integration Patterns server.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;[&amp;amp;apos;Severity: low \n\nAffected versions:\n\n- Apache ActiveMQ Client (org.apache.activemq:activemq-client) before 5.19.3\n- Apache ActiveMQ Client (org.apache.activemq:activemq-client) 6.0.0 before 6.2.2\n- Apache ActiveMQ Broker (org.apache.activemq:activemq-broker) before 5.19.3\n- Apache ActiveMQ Broker (org.apache.activemq:activemq-broker) 6.0.0 before 6.2.2\n- Apache ActiveMQ (org.apache.activemq:activemq-all) before 5.19.3\n- Apache ActiveMQ (org.apache.activemq:activemq-all) 6.0.0 before 6.2.2\n- Apache ActiveMQ Web (org.apache.activemq:activemq-web) before 5.19.3\n- Apache ActiveMQ Web (org.apache.activemq:activemq-web) 6.0.0 before 6.2.2\n\nDescription:\n\nImproper validation and restriction of a classpath path name vulnerability in Apache ActiveMQ Client, Apache ActiveMQ \nBroker, Apache ActiveMQ All.\n\nIn two instances (when creating a Stomp consumer and also browsing messages in the Web console) an authenticated user \nprovided &amp;amp;quot;key&amp;amp;quot; value could be constructed to traverse the classpath due to path concatenation. As a result, the \napplication is exposed to a classpath path resource loading vulnerability that could potentially be chained together \nwith another attack to lead to exploit.This issue affects Apache ActiveMQ Client: before 5.19.3, from 6.0.0 before \n6.2.2; Apache ActiveMQ Broker: before 5.19.3, from 6.0.0 before 6.2.2; Apache Activ…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2124</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-34197</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-34197</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: activemq, Ubuntu:Pro:18.04:LTS: activemq, Ubuntu:Pro:20.04:LTS: activemq, Ubuntu:Pro:22.04:LTS: activemq, Ubuntu:24.04:LTS: activemq, Ubuntu:25.10: activemq, Ubuntu:26.04:LTS: activemq&lt;/p&gt;
&lt;p&gt;Improper Input Validation, Improper Control of Generation of Code (&amp;#39;Code Injection&amp;#39;) vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport&amp;#39;s brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. Because Spring&amp;#39;s ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker&amp;#39;s JVM through bean factory methods such as Runtime.exec(). This issue affects Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ All: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.3. Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: activemq, Ubuntu:Pro:18.04:LTS: activemq, Ubuntu:Pro:20.04:LTS: activemq, Ubuntu:Pro:22.04:LTS: activemq, Ubuntu:24.04:LTS: activemq, Ubuntu:25.10: activemq, Ubuntu:26.04:LTS: activemq&lt;/p&gt;
&lt;p&gt;Improper Input Validation, Improper Control of Generation of Code (&amp;#39;Code Injection&amp;#39;) vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans (org.apache.activemq:*), including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker can invoke these operations with a crafted discovery URI that triggers the VM transport&amp;#39;s brokerConfig parameter to load a remote Spring XML application context using ResourceXmlApplicationContext. Because Spring&amp;#39;s ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, arbitrary code execution occurs on the broker&amp;#39;s JVM through bean factory methods such as Runtime.exec(). This issue affects Apache ActiveMQ Broker: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ All: before 5.19.4, from 6.0.0 before 6.2.3; Apache ActiveMQ: before 5.19.4, from 6.0.0 before 6.2.3. Users are recommended to upgrade to version 5.19.4 or 6.2.3, which fixes the issue&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-34197</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0991 — Apache ActiveMQ, Client, Broker und Web: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0991</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Apache ActiveMQ ausnutzen, um Dateien zu manipulieren oder beliebigen Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Apache ActiveMQ ausnutzen, um Dateien zu manipulieren oder beliebigen Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0991</guid>
    </item>
  </channel>
</rss>
