Known Vulnerabilities for Apache ActiveMQ Broker by Apache Software Foundation
Listed below are 10 of the newest known vulnerabilities associated with "Apache ActiveMQ Broker" by "Apache Software Foundation".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-101292 json | Apache ActiveMQ Artemis before 2.34.0 contains an unsafe reflection vulnerability in FederationStreamConnectMessage.getFedera... | Not Provided | 2026-09-28 | 2026-09-29 |
| CVE-2026-75880 json | An authenticated client could attach a consumer with a selector containing crafted wildcard usage that results in excessive e... | Not Provided | 2026-09-10 | 2026-09-18 |
| CVE-2026-74761 json | Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All on all platform... | Not Provided | 2026-09-09 | 2026-09-10 |
| CVE-2026-67593 json | A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-61487 json | Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated low-... | Not Provided | 2026-07-28 | 2026-07-28 |
| CVE-2026-57822 json | When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-49362 json | An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker ... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-43866 json | Deserialization of Untrusted Data vulnerability in Apache Camel, Apache Camel JMS component. JmsBinding.extractBodyFromJms()... | Not Provided | 2026-07-06 | 2026-07-06 |
| CVE-2026-41044 json | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ, Apache... | Not Provided | 2026-04-24 | 2026-07-15 |
| CVE-2026-40466 json | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker,... | Not Provided | 2026-04-24 | 2026-07-15 |