Multiple vulnerabilities affecting Apache Artemis versions These ActiveMQ Artemis flaws impact a wide range of deployments have been identified in Apache Artemis and ActiveMQ Artemis protocol handling and core authentication mechanisms. These flaws allow malicious actors to steal sessions, expose credentials, and execute denial of service attacks.
CVE-2026-67593 (CVSS 9.1 — Critical): An attacker exploits the Openwire RemoveSubscriptionInfo command to delete a queue before connection authentication.[/subscribe_to_unlock_form]
Multiple vulnerabilities affecting Apache Artemis versions These ActiveMQ Artemis flaws impact a wide range of deployments have been identified in Apache Artemis and ActiveMQ Artemis protocol handling and core authentication mechanisms. These flaws allow malicious actors to steal sessions, expose credentials, and execute denial of service attacks.
CVE-2026-67593 (CVSS 9.1 — Critical): An attacker exploits the Openwire RemoveSubscriptionInfo command to delete a queue before connection authentication.[emaillocker id="1283"]
CVE-2026-57967 (CVSS 9.8 — Critical): An unauthenticated remote attacker crafts a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session.
CVE-2026-49362 (CVSS 7.5 — High): AAn unauthenticated user can create arbitrary durable queues through the CORE protocol, causing unauthorized broker state manipulation and potential denial of service.
CVE-2026-49364 (CVSS 9.1 — Critical): Cluster administrative credentials are exposed during initial connection handshakes.
CVE-2026-57822 (CVSS 6.5 — Medium): Authenticated users send specific management requests to trigger excessive computation and cause a denial of service.
We recommend you to upgrade Apache Artemis to version 2.57.0 or later.
The following reports contain further technical details:
[/emaillocker]