Apache ActiveMQ security advisory (AV26-330) - Update 1

Serial number: AV26-330
Date: April 8, 2026
Update: April 16, 2026

On April 8, 2026, Apache published a security advisory to address a vulnerability in the following products:

  • Apache ActiveMQ Broker - versions prior to 5.19.4
  • Apache ActiveMQ Broker - 6.0.0 versions prior to 6.2.3

Update 1

On April 16, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-34197 to their Known Exploited Vulnerabilities (KEV) Database.

The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates.

Date modified: