Apache ActiveMQ Deserialization of Untrusted Data Vulnerability

Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath.

Published 31 Aug 2026Updated 31 Aug 2026201 sources
CVSS 0.0 PoC CANDIDATE△ CISA KEV

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.