SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-49364

CRITICAL · CVSS 9.1 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

Apache Artemis and Apache ActiveMQ Artemis versions 2.50.0 to 2.56.0 and 1.0.0 to 2.44.0 are vulnerable to an unauthenticated network-adjacent attack that allows the capture of cluster administrative credentials during the initial connection handshake. This vulnerability poses a significant risk as it could enable attackers to gain unauthorized access to cluster management functions. Organizations using these versions should prioritize upgrading to version 2.57.0 to mitigate this security risk.

CVE
CVE-2026-49364
Severity
CRITICAL
CVSS
9.1
EPSS
0.29%
Apache

Original NVD Description

An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.