Pull down to go back
6,400 Unpatched Apache ActiveMQ Servers Still Vulnerable to Remote Code Execution—Urgent Update Required

6,400 Unpatched Apache ActiveMQ Servers Still Vulnerable to Remote Code Execution—Urgent Update Required

未修補漏洞的Apache ActiveMQ主機仍有6,400臺,暴露於遠端執行程式碼攻擊風險下,用戶需儘速更新

Last week, we reported on a critical Apache ActiveMQ vulnerability (CVE-2026-34197) that had lurked undetected for 13 years, discovered by Horizon3.ai researchers with help from AI tool Claude. The discovery sparked headlines about AI's role in finding security flaws, but it also quickly caught the attention of attackers. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has now added this vulnerability to its Known Exploited Vulnerabilities (KEV) list, demanding that organizations patch their systems by April 30th. Security researchers estimate that roughly 6,400 ActiveMQ instances remain unpatched and exposed to remote code execution attacks.