Mark RadarMARK RADAR
EN

13-Year-Old High-Risk Apache ActiveMQ Flaw Discovered With Claude's Help

5 reports · First detected 2026-04-13 · Last active 2026-04-23

Apache ActiveMQ is an open-source message broker widely used to transfer data between enterprise systems. The vulnerability, tracked as CVE-2026-34197, had existed for about 13 years. It could allow attackers to remotely execute code without authorization and take control of servers, posing risks to supply chains and critical information systems.

Researchers at cybersecurity firm Horizon3.ai discovered the flaw with assistance from Anthropic's Claude AI tool. The Apache Software Foundation has since issued a security advisory and patch, while CISA has warned that the vulnerability is being actively exploited. As of April 23, about 6,400 unpatched ActiveMQ hosts remained exposed to attack.

All Coverage

5 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR