Database/Control plane, storage & DevOps
Apache ActiveMQ: Improper input validation and code injection in the broker
CVSS 8.8CVE-2026-34197Control plane, storage & DevOpsKnown exploitedcurated
Impact
Improper input validation and code injection in the broker
Who can reach it
Network (remote)
What to do
Control-plane: broker upgrade; ActiveMQ is a recurring ransomware entry point
References
Related entries
- Supermicro SMASH service (X14DBG-DAP, X14DBI): An attacker with any authorised BMC login escalates through the SMASHCVE-2026-3821 · Supermicro SMASH service (X14DBG-DAP, X14DBI)High
- Ceph RGW: unauthenticated STS token encryption lets any token holder bit-flip themselves to RGW adminCVE-2026-39944 · Ceph RADOS Gateway (STS session token AES-128-CBC handler)High
- MinIO (S3 API, Snowball auto-extract): The Snowball auto-extract path skips signature verification entirely, so anCVE-2026-40344 · MinIO (S3 API, Snowball auto-extract)High
- MinIO (S3 API, unsigned-trailer uploads): The signature on a query-string-credential unsigned-trailer upload is notCVE-2026-41145 · MinIO (S3 API, unsigned-trailer uploads)High
- JFrog Artifactory: token scope not validated, allowing privilege escalation from any low-privileged tokenCVE-2026-42016 · JFrog Artifactory Self-Hosted (access token scope validation)High
- OpenCost: unauthenticated POST /serviceKey overwrites the GCP service-account key fileCVE-2026-44300 · OpenCost (POST /serviceKey endpoint in pkg/costmodel/router.go)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.