{"schema_version":1,"title":"Apache ActiveMQ Artemis vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 15 vulnerabilities in Apache ActiveMQ Artemis: 0 in the last 7 days and 7 in the last 90 days, 4 of them critical and 0 exploited in the wild. The most recent, CVE-2026-75880, was published on 10 September 2026.","url":"https://junglewise.ai/threats/technologies/activemq-artemis","json_url":"https://junglewise.ai/threats/technologies/activemq-artemis.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/activemq-artemis","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":4,"all_time":15,"critical":4,"exploited":0,"last_7_days":0,"last_30_days":7,"last_90_days":7,"last_365_days":10},"latest":[{"cve":"CVE-2026-75880","cvss":6.5,"epss":0.0065,"slug":"cve-2026-75880-apache-activemq-artemis-denial-of-service-via-crafted-wildcard","title":"Apache ActiveMQ Artemis denial of service via crafted wildcard selector","severity":"medium","exploited":false,"published_at":"2026-09-10T05:17:01.673+00:00","url":"https://junglewise.ai/threats/cve-2026-75880-apache-activemq-artemis-denial-of-service-via-crafted-wildcard"},{"cve":"CVE-2026-67593","cvss":9.1,"epss":0.0086,"slug":"cve-2026-67593-apache-artemis-openwire-removesubscriptioninfo-unauthenticated","title":"Apache Artemis Openwire RemoveSubscriptionInfo unauthenticated queue deletion","severity":"critical","exploited":false,"published_at":"2026-09-10T05:17:01.56+00:00","url":"https://junglewise.ai/threats/cve-2026-67593-apache-artemis-openwire-removesubscriptioninfo-unauthenticated"},{"cve":"CVE-2026-57967","cvss":9.8,"epss":0.0107,"slug":"cve-2026-57967-apache-artemis-core-protocol-session-reattach-authentication","title":"Apache Artemis CORE protocol session reattach authentication bypass","severity":"critical","exploited":false,"published_at":"2026-09-10T05:17:01.443+00:00","url":"https://junglewise.ai/threats/cve-2026-57967-apache-artemis-core-protocol-session-reattach-authentication"},{"cve":"CVE-2026-57822","cvss":6.5,"epss":0.0071,"slug":"cve-2026-57822-apache-artemis-java-deserialization-denial-of-service-in-message","title":"Apache Artemis Java deserialization denial of service in message management","severity":"medium","exploited":false,"published_at":"2026-09-10T05:17:01.343+00:00","url":"https://junglewise.ai/threats/cve-2026-57822-apache-artemis-java-deserialization-denial-of-service-in-message"},{"cve":"CVE-2026-49364","cvss":9.1,"epss":0.0057,"slug":"cve-2026-49364-apache-artemis-credential-exposure-during-cluster-handshake","title":"Apache Artemis credential exposure during cluster handshake","severity":"critical","exploited":false,"published_at":"2026-09-10T05:17:01.23+00:00","url":"https://junglewise.ai/threats/cve-2026-49364-apache-artemis-credential-exposure-during-cluster-handshake"},{"cve":"CVE-2026-49363","cvss":7.5,"epss":0.008,"slug":"cve-2026-49363-apache-artemis-cluster-topology-disclosure-via-subscribe-topology","title":"Apache Artemis cluster topology disclosure via SUBSCRIBE_TOPOLOGY","severity":"high","exploited":false,"published_at":"2026-09-10T05:17:01.123+00:00","url":"https://junglewise.ai/threats/cve-2026-49363-apache-artemis-cluster-topology-disclosure-via-subscribe-topology"},{"cve":"CVE-2026-49362","cvss":7.5,"epss":0.0082,"slug":"cve-2026-49362-apache-artemis-unauthenticated-queue-creation-via-core-protocol","title":"Apache Artemis unauthenticated queue creation via CORE protocol","severity":"high","exploited":false,"published_at":"2026-09-10T05:16:59.747+00:00","url":"https://junglewise.ai/threats/cve-2026-49362-apache-artemis-unauthenticated-queue-creation-via-core-protocol"},{"cve":"CVE-2026-40914","cvss":4.3,"epss":0.0056,"slug":"cve-2026-40914-apache-artemis-authorization-bypass-in-stomp-protocol","title":"Apache Artemis authorization bypass in STOMP protocol","severity":"medium","exploited":false,"published_at":"2026-05-28T13:16:23.013+00:00","url":"https://junglewise.ai/threats/cve-2026-40914-apache-artemis-authorization-bypass-in-stomp-protocol"},{"cve":"CVE-2026-32642","cvss":4.3,"epss":0.0056,"slug":"cve-2026-32642-apache-activemq-artemis-incorrect-authorization-in-openwire","title":"Apache ActiveMQ Artemis incorrect authorization in OpenWire protocol","severity":"medium","exploited":false,"published_at":"2026-03-24T08:16:01.43+00:00","url":"https://junglewise.ai/threats/cve-2026-32642-apache-activemq-artemis-incorrect-authorization-in-openwire"},{"cve":"CVE-2026-27446","cvss":9.8,"epss":0.0114,"slug":"cve-2026-27446-apache-activemq-artemis-authentication-bypass-in-core-protocol","title":"Apache ActiveMQ Artemis authentication bypass in Core protocol","severity":"critical","exploited":false,"published_at":"2026-03-04T09:15:56.837+00:00","url":"https://junglewise.ai/threats/cve-2026-27446-apache-activemq-artemis-authentication-bypass-in-core-protocol"},{"cve":"CVE-2022-35278","cvss":6.1,"epss":0.0171,"slug":"cve-2022-35278-apache-activemq-artemis-html-injection-in-web-console","title":"Apache ActiveMQ Artemis HTML injection in Web Console","severity":"medium","exploited":false,"published_at":"2022-08-24T00:00:29+00:00","url":"https://junglewise.ai/threats/cve-2022-35278-apache-activemq-artemis-html-injection-in-web-console"},{"cve":"CVE-2020-10727","cvss":5.5,"epss":0.007,"slug":"cve-2020-10727-apache-activemq-artemis-plaintext-password-storage-in-resetusers","title":"Apache ActiveMQ Artemis plaintext password storage in resetUsers operation","severity":"medium","exploited":false,"published_at":"2022-05-24T17:21:42+00:00","url":"https://junglewise.ai/threats/cve-2020-10727-apache-activemq-artemis-plaintext-password-storage-in-resetusers"},{"cve":"CVE-2020-13932","cvss":6.1,"epss":0.0435,"slug":"cve-2020-13932-apache-activemq-artemis-xss-in-admin-console-diagram-plugin","title":"Apache ActiveMQ Artemis XSS in admin console diagram plugin","severity":"medium","exploited":false,"published_at":"2022-02-09T22:14:01+00:00","url":"https://junglewise.ai/threats/cve-2020-13932-apache-activemq-artemis-xss-in-admin-console-diagram-plugin"},{"cve":"CVE-2022-23913","cvss":7.5,"epss":0.0274,"slug":"cve-2022-23913-apache-activemq-artemis-dos-via-uncontrolled-memory-consumption","title":"Apache ActiveMQ Artemis DoS via uncontrolled memory consumption","severity":"high","exploited":false,"published_at":"2022-02-06T00:00:55+00:00","url":"https://junglewise.ai/threats/cve-2022-23913-apache-activemq-artemis-dos-via-uncontrolled-memory-consumption"},{"cve":"CVE-2021-26118","cvss":7.5,"epss":0.0392,"slug":"cve-2021-26118-apache-activemq-artemis-improper-access-control-in-openwire","title":"Apache ActiveMQ Artemis improper access control in OpenWire protocol","severity":"high","exploited":false,"published_at":"2021-06-16T17:39:05+00:00","url":"https://junglewise.ai/threats/cve-2021-26118-apache-activemq-artemis-improper-access-control-in-openwire"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":3,"exploited":0,"vulnerabilities":7},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Apache Tomcat","slug":"tomcat","vulnerabilities":78,"url":"https://junglewise.ai/threats/technologies/tomcat"},{"name":"Apache Airflow","slug":"airflow","vulnerabilities":63,"url":"https://junglewise.ai/threats/technologies/airflow"},{"name":"Apache Camel","slug":"camel","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/camel"},{"name":"Apache Traffic Server","slug":"traffic-server","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/traffic-server"},{"name":"Apache HTTP Server","slug":"http-server","vulnerabilities":32,"url":"https://junglewise.ai/threats/technologies/http-server"},{"name":"Apache CloudStack","slug":"cloudstack","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/cloudstack"},{"name":"Apache Ofbiz","slug":"ofbiz","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/ofbiz"},{"name":"Apache ActiveMQ","slug":"activemq","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/activemq"},{"name":"Apache Storm","slug":"storm","vulnerabilities":17,"url":"https://junglewise.ai/threats/technologies/storm"},{"name":"Apache Apisix","slug":"apisix","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/apisix"},{"name":"Apache Thrift","slug":"thrift","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/thrift"},{"name":"Apache Ranger","slug":"ranger","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/ranger"}],"technology":{"hub":true,"name":"Apache ActiveMQ Artemis","slug":"activemq-artemis","vendor":{"name":"Apache","slug":"apache","url":"https://junglewise.ai/threats/vendors/apache"},"aliases":[],"category":"message-broker","homepage":"https://activemq.apache.org/components/artemis/","repo_url":"https://github.com/apache/activemq-artemis","description":"An asynchronous messaging system designed for high performance and high availability.","url":"https://junglewise.ai/threats/technologies/activemq-artemis"},"most_severe":[{"cve":"CVE-2026-27446","cvss":9.8,"epss":0.0114,"slug":"cve-2026-27446-apache-activemq-artemis-authentication-bypass-in-core-protocol","title":"Apache ActiveMQ Artemis authentication bypass in Core protocol","severity":"critical","exploited":false,"published_at":"2026-03-04T09:15:56.837+00:00","url":"https://junglewise.ai/threats/cve-2026-27446-apache-activemq-artemis-authentication-bypass-in-core-protocol"},{"cve":"CVE-2026-57967","cvss":9.8,"epss":0.0107,"slug":"cve-2026-57967-apache-artemis-core-protocol-session-reattach-authentication","title":"Apache Artemis CORE protocol session reattach authentication bypass","severity":"critical","exploited":false,"published_at":"2026-09-10T05:17:01.443+00:00","url":"https://junglewise.ai/threats/cve-2026-57967-apache-artemis-core-protocol-session-reattach-authentication"},{"cve":"CVE-2026-67593","cvss":9.1,"epss":0.0086,"slug":"cve-2026-67593-apache-artemis-openwire-removesubscriptioninfo-unauthenticated","title":"Apache Artemis Openwire RemoveSubscriptionInfo unauthenticated queue deletion","severity":"critical","exploited":false,"published_at":"2026-09-10T05:17:01.56+00:00","url":"https://junglewise.ai/threats/cve-2026-67593-apache-artemis-openwire-removesubscriptioninfo-unauthenticated"},{"cve":"CVE-2026-49364","cvss":9.1,"epss":0.0057,"slug":"cve-2026-49364-apache-artemis-credential-exposure-during-cluster-handshake","title":"Apache Artemis credential exposure during cluster handshake","severity":"critical","exploited":false,"published_at":"2026-09-10T05:17:01.23+00:00","url":"https://junglewise.ai/threats/cve-2026-49364-apache-artemis-credential-exposure-during-cluster-handshake"},{"cve":"CVE-2021-26118","cvss":7.5,"epss":0.0392,"slug":"cve-2021-26118-apache-activemq-artemis-improper-access-control-in-openwire","title":"Apache ActiveMQ Artemis improper access control in OpenWire protocol","severity":"high","exploited":false,"published_at":"2021-06-16T17:39:05+00:00","url":"https://junglewise.ai/threats/cve-2021-26118-apache-activemq-artemis-improper-access-control-in-openwire"},{"cve":"CVE-2022-23913","cvss":7.5,"epss":0.0274,"slug":"cve-2022-23913-apache-activemq-artemis-dos-via-uncontrolled-memory-consumption","title":"Apache ActiveMQ Artemis DoS via uncontrolled memory consumption","severity":"high","exploited":false,"published_at":"2022-02-06T00:00:55+00:00","url":"https://junglewise.ai/threats/cve-2022-23913-apache-activemq-artemis-dos-via-uncontrolled-memory-consumption"},{"cve":"CVE-2026-49362","cvss":7.5,"epss":0.0082,"slug":"cve-2026-49362-apache-artemis-unauthenticated-queue-creation-via-core-protocol","title":"Apache Artemis unauthenticated queue creation via CORE protocol","severity":"high","exploited":false,"published_at":"2026-09-10T05:16:59.747+00:00","url":"https://junglewise.ai/threats/cve-2026-49362-apache-artemis-unauthenticated-queue-creation-via-core-protocol"},{"cve":"CVE-2026-49363","cvss":7.5,"epss":0.008,"slug":"cve-2026-49363-apache-artemis-cluster-topology-disclosure-via-subscribe-topology","title":"Apache Artemis cluster topology disclosure via SUBSCRIBE_TOPOLOGY","severity":"high","exploited":false,"published_at":"2026-09-10T05:17:01.123+00:00","url":"https://junglewise.ai/threats/cve-2026-49363-apache-artemis-cluster-topology-disclosure-via-subscribe-topology"},{"cve":"CVE-2026-57822","cvss":6.5,"epss":0.0071,"slug":"cve-2026-57822-apache-artemis-java-deserialization-denial-of-service-in-message","title":"Apache Artemis Java deserialization denial of service in message management","severity":"medium","exploited":false,"published_at":"2026-09-10T05:17:01.343+00:00","url":"https://junglewise.ai/threats/cve-2026-57822-apache-artemis-java-deserialization-denial-of-service-in-message"},{"cve":"CVE-2026-75880","cvss":6.5,"epss":0.0065,"slug":"cve-2026-75880-apache-activemq-artemis-denial-of-service-via-crafted-wildcard","title":"Apache ActiveMQ Artemis denial of service via crafted wildcard selector","severity":"medium","exploited":false,"published_at":"2026-09-10T05:17:01.673+00:00","url":"https://junglewise.ai/threats/cve-2026-75880-apache-activemq-artemis-denial-of-service-via-crafted-wildcard"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}