๐Ÿ” CVE Alert

CVE-2026-40046

HIGH 7.5

Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT: Missing fix for CVE-2025-66168: MQTT control packet remaining length field is not properly validated

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
4th

Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT. The fix for "CVE-2025-66168: MQTT control packet remaining length field is not properly validated" was only applied to 5.19.2 (and future 5.19.x) releases but was missed for all 6.0.0+ versions. This issue affects Apache ActiveMQ: from 6.0.0 before 6.2.4; Apache ActiveMQ All: from 6.0.0 before 6.2.4; Apache ActiveMQ MQTT: from 6.0.0 before 6.2.4. Users are recommended to upgrade to version 6.2.4 or a 5.19.x version starting with 5.19.2 or later (currently latest is 5.19.5), which fixes the issue.

CWE CWE-190
Vendor apache software foundation
Product apache activemq
Published Apr 9, 2026
Last Updated Apr 10, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache activemq

Be the first to know when new high vulnerabilities affecting apache software foundation apache activemq are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Apache Software Foundation / Apache ActiveMQ
6.0.0 < 6.2.4
Apache Software Foundation / Apache ActiveMQ All
6.0.0 < 6.2.4
Apache Software Foundation / Apache ActiveMQ MQTT
6.0.0 < 6.2.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
cve.org: https://www.cve.org/CVERecord?id=CVE-2025-66168 activemq.apache.org: https://activemq.apache.org/security-advisories.data/CVE-2026-40046-announcement.txt lists.apache.org: https://lists.apache.org/thread/zdntj5rcgjjzrpow84o339lzldy68zrg

Credits

Adrien Bernard