Apache ActiveMQ Artemis
7 known vulnerabilities in Apache ActiveMQ Artemis, 3 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-75880 CVSS 6.5 medium An authenticated client could attach a consumer with a selector containing crafted wildcard usage that results in excessive evaluation…
- CVE-2026-67593 CVSS 9.1 critical A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the…
- CVE-2026-57967 CVSS 9.8 critical An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing…
- CVE-2026-57822 CVSS 6.5 medium When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE…
- CVE-2026-49364 CVSS 9.1 critical An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial…
- CVE-2026-49363 CVSS 7.5 high An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY…
- CVE-2026-49362 CVSS 7.5 high An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state…