[UPDATE] [hoch] Apache ActiveMQ: Mehrere Schwachstellen
Ein Angreifer kann mehrere Schwachstellen in Apache ActiveMQ ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, Informationen offenzulegen, seine Rechte zu erweitern, Daten zu manipulieren und Code auszuführen.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1741
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2026-422531.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 64% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-425880.74% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 53% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-455050.60% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 47% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-466050.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-491570.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-492700.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-42253 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-42588 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-45505 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-46605 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-49157 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-49270 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highexploited[UPDATE] [hoch] IBM QRadar SIEM: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: …cert-bund
- unknownexploitedMultiples vulnérabilités dans les produits IBM (28 août 2026)cert-fr-avis
- unknownMultiple vulnerabilities in IBM products (July 31, 2026)cert-fr-avis
- highGHSA-99qx-5qqr-4j95: Apache ActiveMQ has an Incorrect Default Permissions vulnerabilityghsa
- mediumGHSA-cpw7-g3p5-qrfq: Apache ActiveMQ server has an incomplete authorization workflowghsa
- mediumGHSA-hf52-78x8-6w3w: Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All have an Exposure of Sensitiv…ghsa
- highGHSA-v853-w46p-fv2h: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ have a Code Injection issueghsa
- highGHSA-hg6c-8mvr-jqc9: Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ have a Code Injection issueghsa
- mediumGHSA-8wm6-6fqh-phmc: Apache ActiveMQ, Apache ActiveMQ Web have a Cross-site Scripting issueghsa
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service2026-09-15
- high[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen2026-09-15
- high[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff2026-09-15
- high[NEU] [hoch] MISP: Mehrere Schwachstellen2026-09-15
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen Denial of Service oder unspezifischer Angri…2026-09-15