All verified exploits

CVE-2026-34197 Remote Code Execution via Jolokia JMX Bridge

Deterministic critical Apache ActiveMQ Added cve-verified-cve-2026-34197

Detects Apache ActiveMQ Classic instances before 5.19.4 / 6.2.3 where the Jolokia JMX-HTTP bridge is accessible with default credentials (admin:admin). The addNetworkConnector MBean operation accepts crafted vm:// URIs with brokerConfig parameters that load remote Spring XML application contexts, enabling arbitrary code execution. This bug has existed for 13+ years.

Is your app exploitable through CVE-2026-34197?

Scan your domain free