SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-67593

CRITICAL · CVSS 9.1 EPSS 0.46%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

Apache Artemis and Apache ActiveMQ Artemis versions 2.50.0 through 2.56.0 and 1.0.0 through 2.44.0, respectively, are vulnerable to a remote attack that can exploit the Openwire RemoveSubscriptionInfo command, leading to the unauthorized deletion of queues before or after connection authentication. This vulnerability poses a significant risk to environments relying on these messaging brokers, making it critical for users to prioritize upgrading to version 2.57.0 to mitigate potential data loss and service disruption. Organizations utilizing these affected versions should take immediate action to secure their systems.

CVE
CVE-2026-67593
Severity
CRITICAL
CVSS
9.1
EPSS
0.46%
Apache

Original NVD Description

A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.