Web1 vuln-feed

Finding #85

Inventory item apache-test 2.4.37 (software, apache)
TitleApache ActiveMQ: Apache ActiveMQ Deserialization of Untrusted Data Vulnerability
Matchkeyword / confidence low
Statusnew
First seen2026-06-11T07:35:12Z
Last updated2026-06-11T07:35:12Z
Source advisoryApache ActiveMQ: Apache ActiveMQ Deserialization of Untrusted Data Vulnerability
Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath.

Update status