Known vulnerability record

CVE-2026-34197

Apache ActiveMQ Improper Input Validation Vulnerability

Stable IDcve:CVE-2026-34197Last updatedLast verifiedLegacy review pendingProvenanceCISA KEV + CVE record + EPSS

Apache ActiveMQ Improper Input Validation Vulnerability

Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.

Keep the signals separate

CVSS severityhighScore 8.8 · source CISA-ADP
EPSS probability97.2%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2026-04-16
Ransomware useunknownPreserved as known / unknown, not a truthy default

Dates and provenance

CVE published
2026-04-07
CVE modified
2026-08-17
KEV date added
2026-04-16
Dataset fetched
2026-08-21T03:55:06.367Z

Original records

Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.