CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CVE-2026-74761: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscription clientId

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6704

As cited

Copy frozen at (site build).

vulnerabilities

CVE-2026-74761: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscription clientId

Apache ActiveMQ versions 5.x before 5.19.11 and 6.x before 6.3.2 contain a moderate-severity vulnerability that allows spoofing of RemoveSubscription clientId. The flaw affects multiple ActiveMQ packages across the broker, all-in-one, and core distributions.

Why it matters: Teams running unpatched ActiveMQ instances should upgrade to 5.19.11, 6.3.2, or later to prevent clientId spoofing attacks that could allow unauthorized subscription removal.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary