ActiveMQ Exploited in the Wild via CVE-2026-34197 and CVE-2024-32114

#ActiveMQ is getting exploited in the wild using a pair of bugs that, when chained, give pre-auth RCE. CVE-2026-34197 was “hiding in plain sight” for 13 years and found by Horizon3.ai’s Naveen Sunkavally – using what he described as “80% Claude with 20% gift-wrapping by a human.” It requires authentication, but there's plenty of default admin:admin pairs out there. A second ActiveMQ bug CVE-2024-32114 removes the need for authentication outright. Mercifully, it only affects deprecated versions of the software. h/t also Jonny Rivera ActiveState for flagging/comment and VulnCheck 👉 https://lnkd.in/ekU7Xs_n

These vulnerabilities highlight a crucial point—default credentials are still a massive risk. With many systems running outdated software, it’s a ticking time bomb for organizations not staying updated.

To view or add a comment, sign in

Explore content categories