Signal

Thousands of Apache ActiveMQ instances still unpatched, weeks after an actively exploited hole discovered

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-04-21 11:17 UTCUpdated 2026-04-21 20:28 UTC
rss
securitycso_online
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (2 domains)domains are deduped. counts indicate coverage, not truth.
2 top sources shown
Actively exploited Apache ActiveMQ flaw impacts 6,400 servers
bleepingcomputer_all · News · bleepingcomputer.com · 2026-04-21 11:17 UTC
limited source diversity in top sources
Overview

Nonprofit security organization Shadowserver found that over 6,400 Apache ActiveMQ servers exposed online are vulnerable to ongoing attacks exploiting a high-severity code injection vulnerability.

Score total
1.01
Momentum 24h
2
Posts
2
Origins
2
Source types
1
Duplicate ratio
0%
All evidence
All evidence
Actively exploited Apache ActiveMQ flaw impacts 6,400 servers
bleepingcomputer_all · bleepingcomputer.com · 2026-04-21 11:17 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 2Origin domains: 2Duplicates: -
Showing 2 / 0
Top publishers (this list)
  • CSO Online (1)
  • bleepingcomputer_all (1)
Top origin domains (this list)
  • csoonline.com (1)
  • bleepingcomputer.com (1)