Technology · VMware
VMware RabbitMQ vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 27 vulnerabilities in VMware RabbitMQ: 27 in the last 7 days and 27 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-67421, was published on 25 September 2026.
- Last 7 days
- 27
- Last 90 days
- 27
- Critical, all time
- 0
- Exploited in the wild
- 0
Latest VMware RabbitMQ vulnerabilities
- CVE-2026-67421: RabbitMQ Management XSS via queue name in OAuth UIinfo
- CVE-2026-67413: RabbitMQ JMS topic exchange denial of service via regex wildcard expansioninfo
- CVE-2026-67412: RabbitMQ Federation upstream authorization bypassinfo
- CVE-2026-67408: RabbitMQ denial of service in Stream Management super-stream bindinginfo
- CVE-2026-67407: RabbitMQ MQTT topic permission bypass in regex escapinginfo
- CVE-2026-67242: RabbitMQ OAuth2 token expiry bypass for fractional expinfo
- CVE-2026-67226: RabbitMQ atom exhaustion in user tags managementinfo
- CVE-2026-67225: RabbitMQ stream protocol frame size validation bypassinfo
- CVE-2026-67222: RabbitMQ list_to_atom denial of service in auth_mechanisminfo
- CVE-2026-66078: RabbitMQ protected tag bypass in bulk-delete endpointinfo
- CVE-2026-66073: RabbitMQ atom table exhaustion in management APIinfo
- CVE-2026-66071: RabbitMQ atom exhaustion in OAuth2 JWT scope parsinginfo
- CVE-2026-67236: RabbitMQ insecure authentication cookie in management consoleinfo
- CVE-2026-67233: RabbitMQ authorization bypass in shovel management resourceinfoEPSS 0.3%
- CVE-2026-67405: RabbitMQ missing Origin header validation in WebSocket upgradeinfoEPSS 0.1%
- CVE-2026-67404: RabbitMQ OAuth2 JWKS signature verification bypassinfoEPSS 0.2%
- CVE-2026-67235: RabbitMQ unvalidated content-header BodySize memory exhaustioninfoEPSS 0.3%
- CVE-2026-67231: RabbitMQ trust-store plugin TLS client authentication bypassinfoEPSS 0.3%
- CVE-2026-67229: RabbitMQ denial of service in vhost metadata importinfoEPSS 0.3%
- CVE-2026-67228: RabbitMQ atom table exhaustion denial of service in runtime-parametersinfoEPSS 0.3%
- CVE-2026-67219: RabbitMQ consistent-hash exchange memory exhaustion via unbounded weightinfoEPSS 0.3%
- CVE-2026-67218: RabbitMQ privilege escalation in HTTP API super stream creationinfoEPSS 0.3%
- CVE-2026-66080: RabbitMQ unbound partition count allocation in stream managementinfoEPSS 0.3%
- CVE-2026-66077: RabbitMQ stored XSS in management UI connection detailsinfoEPSS 0.3%
- CVE-2026-66072: RabbitMQ stream protocol atom injection in chunk_selectorinfoEPSS 0.3%
Most severe VMware RabbitMQ vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-66069: RabbitMQ unauthorized auth-attempt metrics resetinfoEPSS 0.4%
- CVE-2026-67218: RabbitMQ privilege escalation in HTTP API super stream creationinfoEPSS 0.3%
- CVE-2026-66072: RabbitMQ stream protocol atom injection in chunk_selectorinfoEPSS 0.3%
- CVE-2026-67238: RabbitMQ atom memory leak denial of serviceinfoEPSS 0.3%
- CVE-2026-67233: RabbitMQ authorization bypass in shovel management resourceinfoEPSS 0.3%
- CVE-2026-66077: RabbitMQ stored XSS in management UI connection detailsinfoEPSS 0.3%
- CVE-2026-67229: RabbitMQ denial of service in vhost metadata importinfoEPSS 0.3%
- CVE-2026-67228: RabbitMQ atom table exhaustion denial of service in runtime-parametersinfoEPSS 0.3%
- CVE-2026-66080: RabbitMQ unbound partition count allocation in stream managementinfoEPSS 0.3%
- CVE-2026-67235: RabbitMQ unvalidated content-header BodySize memory exhaustioninfoEPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 27 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/vmware-rabbitmq.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "VMware RabbitMQ vulnerabilities", https://junglewise.ai/threats/technologies/vmware-rabbitmq, 27 September 2026.