cbcvebase.
CVE-2026-74761
published 2026-09-09

CVE-2026-74761: Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All on all platforms. An authenticated client can…

PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.20%
9.6th percentile
Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All on all platforms. An authenticated client can spoof clientId when removing a durable topic subscription. This issue affects Apache ActiveMQ Broker: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ All: before 5.19.11, from 6.0.0 before 6.3.2; Apache ActiveMQ: before 5.19.11, from 6.0.0 before 6.3.2. Users are recommended to upgrade to version 6.3.2 or 5.19.11 which fixes the issue.

Affected

6 ranges
VendorProductVersion rangeFixed in
apache_software_foundationapache_activemq< 5.19.115.19.11
apache_software_foundationapache_activemq>= 6.0.0 < 6.3.26.3.2
apache_software_foundationapache_activemq_all< 5.19.115.19.11
apache_software_foundationapache_activemq_all>= 6.0.0 < 6.3.26.3.2
apache_software_foundationapache_activemq_broker< 5.19.115.19.11
apache_software_foundationapache_activemq_broker>= 6.0.0 < 6.3.26.3.2
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.