{"schema_version":1,"title":"Apache Artemis vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 10 vulnerabilities in Apache Artemis: 0 in the last 7 days and 7 in the last 90 days, 4 of them critical and 0 exploited in the wild. The most recent, CVE-2026-75880, was published on 10 September 2026.","url":"https://junglewise.ai/threats/technologies/artemis","json_url":"https://junglewise.ai/threats/technologies/artemis.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/artemis","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":2,"all_time":10,"critical":4,"exploited":0,"last_7_days":0,"last_30_days":7,"last_90_days":7,"last_365_days":10},"latest":[{"cve":"CVE-2026-75880","cvss":6.5,"epss":0.0065,"slug":"cve-2026-75880-apache-activemq-artemis-denial-of-service-via-crafted-wildcard","title":"Apache ActiveMQ Artemis denial of service via crafted wildcard selector","severity":"medium","exploited":false,"published_at":"2026-09-10T05:17:01.673+00:00","url":"https://junglewise.ai/threats/cve-2026-75880-apache-activemq-artemis-denial-of-service-via-crafted-wildcard"},{"cve":"CVE-2026-67593","cvss":9.1,"epss":0.0086,"slug":"cve-2026-67593-apache-artemis-openwire-removesubscriptioninfo-unauthenticated","title":"Apache Artemis Openwire RemoveSubscriptionInfo unauthenticated queue deletion","severity":"critical","exploited":false,"published_at":"2026-09-10T05:17:01.56+00:00","url":"https://junglewise.ai/threats/cve-2026-67593-apache-artemis-openwire-removesubscriptioninfo-unauthenticated"},{"cve":"CVE-2026-57967","cvss":9.8,"epss":0.0107,"slug":"cve-2026-57967-apache-artemis-core-protocol-session-reattach-authentication","title":"Apache Artemis CORE protocol session reattach authentication bypass","severity":"critical","exploited":false,"published_at":"2026-09-10T05:17:01.443+00:00","url":"https://junglewise.ai/threats/cve-2026-57967-apache-artemis-core-protocol-session-reattach-authentication"},{"cve":"CVE-2026-57822","cvss":6.5,"epss":0.0071,"slug":"cve-2026-57822-apache-artemis-java-deserialization-denial-of-service-in-message","title":"Apache Artemis Java deserialization denial of service in message management","severity":"medium","exploited":false,"published_at":"2026-09-10T05:17:01.343+00:00","url":"https://junglewise.ai/threats/cve-2026-57822-apache-artemis-java-deserialization-denial-of-service-in-message"},{"cve":"CVE-2026-49364","cvss":9.1,"epss":0.0057,"slug":"cve-2026-49364-apache-artemis-credential-exposure-during-cluster-handshake","title":"Apache Artemis credential exposure during cluster handshake","severity":"critical","exploited":false,"published_at":"2026-09-10T05:17:01.23+00:00","url":"https://junglewise.ai/threats/cve-2026-49364-apache-artemis-credential-exposure-during-cluster-handshake"},{"cve":"CVE-2026-49363","cvss":7.5,"epss":0.008,"slug":"cve-2026-49363-apache-artemis-cluster-topology-disclosure-via-subscribe-topology","title":"Apache Artemis cluster topology disclosure via SUBSCRIBE_TOPOLOGY","severity":"high","exploited":false,"published_at":"2026-09-10T05:17:01.123+00:00","url":"https://junglewise.ai/threats/cve-2026-49363-apache-artemis-cluster-topology-disclosure-via-subscribe-topology"},{"cve":"CVE-2026-49362","cvss":7.5,"epss":0.0082,"slug":"cve-2026-49362-apache-artemis-unauthenticated-queue-creation-via-core-protocol","title":"Apache Artemis unauthenticated queue creation via CORE protocol","severity":"high","exploited":false,"published_at":"2026-09-10T05:16:59.747+00:00","url":"https://junglewise.ai/threats/cve-2026-49362-apache-artemis-unauthenticated-queue-creation-via-core-protocol"},{"cve":"CVE-2026-40914","cvss":4.3,"epss":0.0056,"slug":"cve-2026-40914-apache-artemis-authorization-bypass-in-stomp-protocol","title":"Apache Artemis authorization bypass in STOMP protocol","severity":"medium","exploited":false,"published_at":"2026-05-28T13:16:23.013+00:00","url":"https://junglewise.ai/threats/cve-2026-40914-apache-artemis-authorization-bypass-in-stomp-protocol"},{"cve":"CVE-2026-32642","cvss":4.3,"epss":0.0056,"slug":"cve-2026-32642-apache-activemq-artemis-incorrect-authorization-in-openwire","title":"Apache ActiveMQ Artemis incorrect authorization in OpenWire protocol","severity":"medium","exploited":false,"published_at":"2026-03-24T08:16:01.43+00:00","url":"https://junglewise.ai/threats/cve-2026-32642-apache-activemq-artemis-incorrect-authorization-in-openwire"},{"cve":"CVE-2026-27446","cvss":9.8,"epss":0.0114,"slug":"cve-2026-27446-apache-activemq-artemis-authentication-bypass-in-core-protocol","title":"Apache ActiveMQ Artemis authentication bypass in Core protocol","severity":"critical","exploited":false,"published_at":"2026-03-04T09:15:56.837+00:00","url":"https://junglewise.ai/threats/cve-2026-27446-apache-activemq-artemis-authentication-bypass-in-core-protocol"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":3,"exploited":0,"vulnerabilities":7},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Apache Tomcat","slug":"tomcat","vulnerabilities":67,"url":"https://junglewise.ai/threats/technologies/tomcat"},{"name":"Apache Airflow","slug":"airflow","vulnerabilities":61,"url":"https://junglewise.ai/threats/technologies/airflow"},{"name":"Apache Camel","slug":"camel","vulnerabilities":40,"url":"https://junglewise.ai/threats/technologies/camel"},{"name":"Apache Traffic Server","slug":"traffic-server","vulnerabilities":39,"url":"https://junglewise.ai/threats/technologies/traffic-server"},{"name":"Apache HTTP Server","slug":"http-server","vulnerabilities":31,"url":"https://junglewise.ai/threats/technologies/http-server"},{"name":"Apache CloudStack","slug":"cloudstack","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/cloudstack"},{"name":"Apache Ofbiz","slug":"ofbiz","vulnerabilities":22,"url":"https://junglewise.ai/threats/technologies/ofbiz"},{"name":"Apache ActiveMQ","slug":"activemq","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/activemq"},{"name":"Apache Storm","slug":"storm","vulnerabilities":17,"url":"https://junglewise.ai/threats/technologies/storm"},{"name":"Apache Apisix","slug":"apisix","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/apisix"},{"name":"Apache Thrift","slug":"thrift","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/thrift"},{"name":"Apache ActiveMQ Artemis","slug":"activemq-artemis","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/activemq-artemis"}],"technology":{"hub":true,"name":"Apache Artemis","slug":"artemis","vendor":{"name":"Apache","slug":"apache","url":"https://junglewise.ai/threats/vendors/apache"},"aliases":[],"category":"message-broker","homepage":"https://activemq.apache.org/artemis/","repo_url":"https://github.com/apache/activemq-artemis","description":"An open-source, high-performance, non-blocking message broker.","url":"https://junglewise.ai/threats/technologies/artemis"},"most_severe":[{"cve":"CVE-2026-27446","cvss":9.8,"epss":0.0114,"slug":"cve-2026-27446-apache-activemq-artemis-authentication-bypass-in-core-protocol","title":"Apache ActiveMQ Artemis authentication bypass in Core protocol","severity":"critical","exploited":false,"published_at":"2026-03-04T09:15:56.837+00:00","url":"https://junglewise.ai/threats/cve-2026-27446-apache-activemq-artemis-authentication-bypass-in-core-protocol"},{"cve":"CVE-2026-57967","cvss":9.8,"epss":0.0107,"slug":"cve-2026-57967-apache-artemis-core-protocol-session-reattach-authentication","title":"Apache Artemis CORE protocol session reattach authentication bypass","severity":"critical","exploited":false,"published_at":"2026-09-10T05:17:01.443+00:00","url":"https://junglewise.ai/threats/cve-2026-57967-apache-artemis-core-protocol-session-reattach-authentication"},{"cve":"CVE-2026-67593","cvss":9.1,"epss":0.0086,"slug":"cve-2026-67593-apache-artemis-openwire-removesubscriptioninfo-unauthenticated","title":"Apache Artemis Openwire RemoveSubscriptionInfo unauthenticated queue deletion","severity":"critical","exploited":false,"published_at":"2026-09-10T05:17:01.56+00:00","url":"https://junglewise.ai/threats/cve-2026-67593-apache-artemis-openwire-removesubscriptioninfo-unauthenticated"},{"cve":"CVE-2026-49364","cvss":9.1,"epss":0.0057,"slug":"cve-2026-49364-apache-artemis-credential-exposure-during-cluster-handshake","title":"Apache Artemis credential exposure during cluster handshake","severity":"critical","exploited":false,"published_at":"2026-09-10T05:17:01.23+00:00","url":"https://junglewise.ai/threats/cve-2026-49364-apache-artemis-credential-exposure-during-cluster-handshake"},{"cve":"CVE-2026-49362","cvss":7.5,"epss":0.0082,"slug":"cve-2026-49362-apache-artemis-unauthenticated-queue-creation-via-core-protocol","title":"Apache Artemis unauthenticated queue creation via CORE protocol","severity":"high","exploited":false,"published_at":"2026-09-10T05:16:59.747+00:00","url":"https://junglewise.ai/threats/cve-2026-49362-apache-artemis-unauthenticated-queue-creation-via-core-protocol"},{"cve":"CVE-2026-49363","cvss":7.5,"epss":0.008,"slug":"cve-2026-49363-apache-artemis-cluster-topology-disclosure-via-subscribe-topology","title":"Apache Artemis cluster topology disclosure via SUBSCRIBE_TOPOLOGY","severity":"high","exploited":false,"published_at":"2026-09-10T05:17:01.123+00:00","url":"https://junglewise.ai/threats/cve-2026-49363-apache-artemis-cluster-topology-disclosure-via-subscribe-topology"},{"cve":"CVE-2026-57822","cvss":6.5,"epss":0.0071,"slug":"cve-2026-57822-apache-artemis-java-deserialization-denial-of-service-in-message","title":"Apache Artemis Java deserialization denial of service in message management","severity":"medium","exploited":false,"published_at":"2026-09-10T05:17:01.343+00:00","url":"https://junglewise.ai/threats/cve-2026-57822-apache-artemis-java-deserialization-denial-of-service-in-message"},{"cve":"CVE-2026-75880","cvss":6.5,"epss":0.0065,"slug":"cve-2026-75880-apache-activemq-artemis-denial-of-service-via-crafted-wildcard","title":"Apache ActiveMQ Artemis denial of service via crafted wildcard selector","severity":"medium","exploited":false,"published_at":"2026-09-10T05:17:01.673+00:00","url":"https://junglewise.ai/threats/cve-2026-75880-apache-activemq-artemis-denial-of-service-via-crafted-wildcard"},{"cve":"CVE-2026-40914","cvss":4.3,"epss":0.0056,"slug":"cve-2026-40914-apache-artemis-authorization-bypass-in-stomp-protocol","title":"Apache Artemis authorization bypass in STOMP protocol","severity":"medium","exploited":false,"published_at":"2026-05-28T13:16:23.013+00:00","url":"https://junglewise.ai/threats/cve-2026-40914-apache-artemis-authorization-bypass-in-stomp-protocol"},{"cve":"CVE-2026-32642","cvss":4.3,"epss":0.0056,"slug":"cve-2026-32642-apache-activemq-artemis-incorrect-authorization-in-openwire","title":"Apache ActiveMQ Artemis incorrect authorization in OpenWire protocol","severity":"medium","exploited":false,"published_at":"2026-03-24T08:16:01.43+00:00","url":"https://junglewise.ai/threats/cve-2026-32642-apache-activemq-artemis-incorrect-authorization-in-openwire"}],"generated_at":"2026-09-26T14:07:00.158513+00:00"}