Menu

Post image 1
Post image 2
Post image 3
1 / 3
0

CISA tells feds to patch 13-year-old Apache ActiveMQ bug

theregister·Carly Page·5 months ago
#xhz1NVTW
Reading 0:00
15s threshold

Security CISA tells feds to patch 13-year-old Apache ActiveMQ bug under active attack Bug hiding in plain sight for over a decade lands on KEV list CISA is sounding the alarm on a newly-exploited Apache ActiveMQ bug, ordering federal agencies to patch within two weeks as attackers circle a flaw that's been quietly lurking for more than a decade. The US cybersecurity agency added the bug, tracked as CVE-2026-34197, to its Known Exploited Vulnerabilities (KEV) catalog on Thursday, triggering a Binding Operational Directive (BOD) 22-01 deadline that gives Federal Civilian Executive Branch agencies until April 30 to fix their systems or get ready to explain why not. The bug sits in Apache ActiveMQ, an open source message broker used to shuttle data between applications and services, and allows an authenticated user to execute arbitrary code via the broker's Jolokia management API – effectively turning a messaging workhorse into a remote command runner.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More