Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilitygovernment-vulnerability-cataloginternet-exposed-serviceproof-of-concept-release

Apache ActiveMQ Jolokia Flaws Enable Zero-Credential Remote Code Execution

Updated 21d agoFirst seen May 25, 20264 sources

Active exploitation has been observed against an Apache ActiveMQ remote code execution chain involving the Jolokia management API. VulnCheck reported canary-network hits tied to CVE-2026-34197, which was added to CISA's Known Exploited Vulnerabilities catalog, and said attackers are also using an unauthenticated variant that chains CVE-2024-32114 with CVE-2026-34197 to achieve zero-credential RCE. According to the reporting, CVE-2024-32114 removes authentication from the Jolokia endpoint in ActiveMQ versions 6.0.0 through 6.1.1, exposing the management interface to unauthenticated abuse.

Technical details published by Horizon3.ai describe the RCE path through the Jolokia API, while VulnCheck said observed payloads invoked addNetworkConnector through Jolokia during exploitation. One captured payload referenced a private IP address, indicating the attacker activity may have reused a lab or proof-of-concept configuration, but the exploitation itself was confirmed in the wild. The combined reporting indicates that exposed ActiveMQ instances with vulnerable Jolokia configurations face immediate risk of unauthenticated remote compromise.

Share:
Apache ActiveMQ Jolokia Flaws Enable Zero-Credential Remote Code Execution
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
May 31, 202623d ago

Apache discloses CVE-2026-45505 ActiveMQ Jolokia wrapper bypass

Apache disclosed CVE-2026-45505, an ActiveMQ Jolokia addNetworkConnector discovery wrapper bypass that can lead to code injection and remote code execution on the broker JVM. The advisory says the issue affects versions before 5.19.7 and 6.2.6 and recommends upgrading to those releases.

CVE-2026-45505: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Jolokia `addNetworkConnector` Discovery Wrapper Bypass-Apache Mail Archives
May 25, 202629d ago

Rapid7 opens pull request for Metasploit ActiveMQ Jolokia exploit module

A Rapid7 Metasploit Framework pull request was opened to add an exploit module and documentation for the Apache ActiveMQ Jolokia remote code execution issue tracked as CVE-2026-34197. The reference indicates the proof of concept was working but rough, marking a new public exploit-tooling development after earlier technical disclosure.

Activemq jolokia exploit (CVE-2026-34197) by h00die · Pull Request #21497 · rapid7/metasploit-framework · GitHub
Apr 14, 20262mo ago

VulnCheck observes active exploitation of ActiveMQ Jolokia RCE chain

VulnCheck reported canary network hits showing attackers actively exploiting a chain combining CVE-2024-32114 and CVE-2026-34197 to achieve zero-credential remote code execution against Apache ActiveMQ. The captured payload used the Jolokia API addNetworkConnector method and referenced a private IP address, suggesting a lab or proof-of-concept configuration may have been reused.

Apr 7, 20263mo ago

Horizon3.ai publishes technical disclosure for CVE-2026-34197

Horizon3.ai published a disclosure covering CVE-2026-34197, describing Apache ActiveMQ remote code execution via the Jolokia API. The publication marked a public release of technical details for the flaw.

Jan 1, 20266mo ago

VulnCheck adds CVE-2024-32114 to its KEV list

After confirming exploitation through its canary network, VulnCheck added CVE-2024-32114 to its own Known Exploited Vulnerabilities list. This reflected a newly documented unauthenticated variant of the ActiveMQ Jolokia attack chain that was not listed in CISA KEV.

Dec 29, 20256mo ago

CVE-2026-34197 added to CISA Known Exploited Vulnerabilities catalog

CVE-2026-34197, an Apache ActiveMQ Jolokia-related remote code execution issue, was added to CISA's KEV catalog during the week referenced by VulnCheck. Its inclusion indicated confirmed in-the-wild exploitation.

May 1, 20242y ago

Apache ActiveMQ Jolokia auth bypass affects versions 6.0.0 through 6.1.1

CVE-2024-32114 was identified as removing authentication from the Jolokia endpoint in Apache ActiveMQ versions 6.0.0 through 6.1.1. This issue enabled unauthenticated access that could later be chained with another flaw for remote code execution.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.