As cited
Copy frozen at (site build).
vulnerabilities
CVE-2026-74761: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscription clientId
Apache ActiveMQ versions 5.x before 5.19.11 and 6.x before 6.3.2 contain a moderate-severity vulnerability that allows spoofing of RemoveSubscription clientId. The flaw affects multiple ActiveMQ packages across the broker, all-in-one, and core distributions.
Why it matters: Teams running unpatched ActiveMQ instances should upgrade to 5.19.11, 6.3.2, or later to prevent clientId spoofing attacks that could allow unauthorized subscription removal.
- Source published
- First seen by Cybersecurity Tracker