Threat reportVulnerabilityTL-2026-0337

Apache ActiveMQ Classic RCE via Jolokia JMX-HTTP Bridge (CVE-2026-34197)

highACTIVE

Apache ActiveMQ Classic RCE via Jolokia JMX-HTTP Bridge (TL-2026-0337) is a high-severity software vulnerability scored CVSS 8.8, first published 2026-04-08. It has no confirmed attribution, affects Apache Software Foundation Apache ActiveMQ Classic (activemq-broker), references 1 CVE (CVE-2026-34197), maps to 15 MITRE ATT&CK techniques (T1046, T1059, T1071), and is covered by 9 detection rules and 15 indicators of compromise.

CVSS
8.8/10High
CVEs
1Referenced vulnerabilities
Techniques
15MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
15Indicators of compromise

Key facts for TL-2026-0337

Threat ID
TL-2026-0337
Severity
HIGH
CVSS
8.8 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
financial, healthcare, government, technology, e-commerce, telecommunications, manufacturing, energy
Target regions
North America, Europe, Asia Pacific, Global
Detection rules
9
Indicators of compromise
15

Malware and tooling in Apache ActiveMQ Classic RCE via Jolokia JMX-HTTP Bridge

Malware and tooling: Spring XML application context as payload delivery mechanism, curl/HTTP client targeting Jolokia API

How Apache ActiveMQ Classic RCE via Jolokia JMX-HTTP Bridge works

A 13-year-old code injection vulnerability in Apache ActiveMQ Classic allows authenticated attackers to achieve remote code execution through the Jolokia JMX-HTTP bridge by invoking addNetworkConnector with a crafted VM transport URI that loads malicious Spring XML configuration. On versions 6.0.0-6.1.1, the flaw is effectively unauthenticated due to CVE-2024-32114.

CVE-2026-34197 is a critical remote code execution vulnerability in Apache ActiveMQ Classic that has existed undetected for approximately 13 years. The vulnerability resides in the interaction between ActiveMQ''s Jolokia JMX-HTTP bridge, the broker''s network connector management API, and Spring Framework''s XML application context loading mechanism.

Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console (default port 8161). Following the patch for CVE-2022-41678, which restricted dangerous JDK MBeans, the Jolokia security policy was configured to permit exec operations on all ActiveMQ MBeans (org.apache.activemq:*). This overly permissive allowlist enables invocation of BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String) through the Jolokia REST API.

The exploit chain works as follows: An attacker sends an HTTP POST request to the /api/jolokia/ endpoint, invoking the addNetworkConnector operation on the broker MBean with a specially crafted VM transport URI. The URI contains a brokerConfig=xbean:http:// parameter pointing to an attacker-controlled server hosting a malicious Spring XML configuration file. When ActiveMQ processes the vm:// URI referencing a non-existent broker, it automatically attempts to instantiate a new embedded broker by calling BrokerFactory.createBroker() with the attacker-supplied URL. The xbean: scheme delegates to Spring''s ResourceXmlApplicationContext, which fetches the remote XML file and instantiates all singleton bean definitions — including beans configured to execute arbitrary OS commands via Spring''s MethodInvokingFactoryBean calling Runtime.exec().

Critically, Spring''s ResourceXmlApplicationContext instantiates all singleton beans before the BrokerService validates the configuration, meaning code execution occurs regardless of whether the broker configuration is ultimately valid. This makes exploitation reliable and deterministic.

The vulnerability requires Jolokia authentication, but default credentials (admin:admin) are extremely common in production deployments. On ActiveMQ versions 6.0.0 through 6.1.1, the vulnerability is effectively unauthenticated because CVE-2024-32114 inadvertently exposed the Jolokia API without access control, eliminating the authentication barrier entirely.

The vulnerability was discovered by Naveen Sunkavally of Horizon3.ai using Anthropic''s Claude AI model, which identified the exploit chain in approximately 10 minutes by connecting multiple seemingly benign features into a viable attack path. As Sunkavally noted, ''Each feature in isolation does what it''s supposed to, but they were dangerous together. This is exactly where Claude shone.'' The discovery was described as ''80% Claude with 20% gift-wrapping by a human.''

Apache ActiveMQ has a history of severe RCE vulnerabilities that have been actively exploited in the wild, including CVE-2023-46604 (unauthenticated RCE on the broker port, exploited by ransomware groups and listed in CISA KEV) and CVE-2016-3088 (authenticated web console RCE, also in CISA KEV). Given this pattern, CVE-2026-34197 presents significant risk for mass exploitation, particularly against internet-exposed ActiveMQ instances with default credentials.

MITRE ATT&CK techniques used in TL-2026-0337

discovery

T1046 Network Service Discovery

execution

T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution

command-and-control

T1071 Application Layer Protocol; T1105 Ingress Tool Transfer

defense-evasion

T1078 Valid Accounts; T1211 Exploitation for Stealth

credential-access

T1110 Brute Force

initial-access

T1190 Exploit Public-Facing Application

lateral-movement

T1210 Exploitation of Remote Services

impact

T1489 Service Stop

persistence

T1505 Server Software Component

privilege-escalation

T1548 Abuse Elevation Control Mechanism

resource-development

T1583 Acquire Infrastructure; T1587 Develop Capabilities

Affected products and versions in Apache ActiveMQ Classic RCE via Jolokia JMX-HTTP Bridge

  • Apache Software Foundation — Apache ActiveMQ Classic (activemq-broker)
    Vulnerable versions: before 5.19.4; 6.0.0 through 6.2.2
    Fixed in: 5.19.4; 6.2.3
  • Apache Software Foundation — Apache ActiveMQ Classic (activemq-all)
    Vulnerable versions: before 5.19.4; 6.0.0 through 6.2.2
    Fixed in: 5.19.4; 6.2.3

Remediation for Apache ActiveMQ Classic RCE via Jolokia JMX-HTTP Bridge

Patches

  • Apache ActiveMQ Classic 5.19.4 (for 5.x branch)
  • Apache ActiveMQ Classic 6.2.3 (for 6.x branch)

Immediate actions

  • Upgrade Apache ActiveMQ Classic to version 5.19.4 or 6.2.3 immediately
  • Change default Jolokia credentials (admin:admin) on all ActiveMQ instances
  • Restrict network access to port 8161 (web console/Jolokia) to trusted management networks only
  • Block inbound access to /api/jolokia/ endpoints at the WAF or reverse proxy level
  • Monitor ActiveMQ broker logs for vm:// URIs containing brokerConfig=xbean:http parameters

Workarounds

  • Disable the Jolokia JMX-HTTP bridge if not required for operations
  • Restrict Jolokia access policy to deny exec operations on BrokerService MBeans
  • Place ActiveMQ web console behind VPN or IP-restricted access control
  • Configure firewall rules to block outbound HTTP connections from the ActiveMQ process

Longer-term hardening

  • Implement network segmentation to isolate message broker infrastructure from general network access
  • Deploy web application firewall rules to detect and block Jolokia exploitation attempts
  • Implement EDR with behavioral detection for unexpected child processes spawned by Java/ActiveMQ processes
  • Establish vulnerability management process for ActiveMQ with automated patch deployment
  • Audit all ActiveMQ deployments for default credentials and internet exposure
  • Consider mutual TLS for Jolokia API access to prevent credential-based attacks

CVEs associated with Apache ActiveMQ Classic RCE via Jolokia JMX-HTTP Bridge

CVE-2026-34197

Weaknesses (CWE) in Apache ActiveMQ Classic RCE via Jolokia JMX-HTTP Bridge

CWE-20, CWE-94

Timeline of Apache ActiveMQ Classic RCE via Jolokia JMX-HTTP Bridge

  • Vulnerable code path introduced in Apache ActiveMQ Classic codebase approximately 13 years before discovery, enabling addNetworkConnector to process vm:// URIs with external brokerConfig parameters
  • CVE-2022-41678 patched with overly permissive Jolokia allowlist that permitted exec operations on all ActiveMQ MBeans (org.apache.activemq:*), inadvertently creating the conditions for CVE-2026-34197
  • CVE-2024-32114 disclosed, revealing that ActiveMQ versions 6.0.0-6.1.1 exposed the Jolokia API without authentication, making any Jolokia-based exploit chain effectively unauthenticated on those versions
  • Naveen Sunkavally of Horizon3.ai reports CVE-2026-34197 to Apache ActiveMQ maintainers after discovering the vulnerability using Claude AI model in approximately 10 minutes
  • Apache Software Foundation releases patched versions ActiveMQ Classic 5.19.4 and 6.2.3, removing the ability for addNetworkConnector to instantiate vm:// transports and eliminating the code execution path
  • CVE-2026-34197 notification posted to the OSS-Security mailing list (openwall.com/lists/oss-security/2026/04/06/3)
  • CVE-2026-34197 officially published with CVSS 8.8 HIGH rating (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
  • Public disclosure by Horizon3.ai with detailed technical analysis and Apache publishes official security advisory for CVE-2026-34197
  • Public proof-of-concept exploit code available on GitHub, demonstrating the full exploit chain from Jolokia API call to arbitrary command execution via Spring XML payload
  • Widespread media coverage from BleepingComputer, GBHackers, CyberSecurityNews, and Infosecurity Magazine highlighting the AI-assisted discovery and 13-year exposure window
  • As of 2026-05-29, CVE-2026-34197 (ActiveMQ Jolokia RCE) is a live concern: despite the Mar-30 patch (5.19.4/6.2.3), CISA added it to KEV on Apr-17 citing active in-the-wild exploitation, with Fortinet seeing attacks peak Apr-14, public PoC, and ~6,400 exposed instances. Patch exists but exploitation is ongoing and ransomware risk is high.

Sources cited for Apache ActiveMQ Classic RCE via Jolokia JMX-HTTP Bridge

Detection coverage for TL-2026-0337

As of 2026-04-08, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0337 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
15 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats