CVE-2026-34197: Apache ActiveMQ Jolokia RCE Under Active Exploitation — 6,400 Servers Exposed
CISA added CVE-2026-34197 to its KEV catalog on April 16 after confirmed active exploitation. Over 6,400 Apache ActiveMQ instances are publicly reachable and vulnerable, with 1,334 in Europe alone. Here is what the attack looks like and what to fix.