CISA tells feds to patch 13-year-old Apache ActiveMQ bug under active attack

2026-04-18T07:23:57Z38f26268d9e47ae7056af546d6b79eaa28b795487fa9eae67e534df8c6b8a11d
AI securityAnthropicApache ActiveMQCISAFortinetGitHub agentsKEVMicrosoft ExcelPatch Tuesdayactive exploitationcredential theftdata breachiPhone bugmacOS social engineeringpatchingprompt injectionransomwaresecurity advisoryzero-day

What happened

A recent security news roundup highlights several actively exploited and high-risk issues: CISA has added a 13-year-old Apache ActiveMQ vulnerability to its KEV list and ordered federal agencies to patch within two weeks; a 17-year-old critical Microsoft Excel flaw is being exploited in the wild; Fortinet disclosed two critical sandbox bugs that can bypass authentication or execute code; and Microsoft published a large Patch Tuesday with one CVE already under attack. The feed also covers multiple AI-related risks (Anthropic MCP design concerns, prompt-injection attacks against AI agents that I

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
38f26268d9e47ae7056af546d6b79eaa28b795487fa9eae67e534df8c6b8a11d
Enrichment time
2026-04-18T07:23:57Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · CISA tells feds to patch 13-year-old Apache ActiveMQ bug under active attack · Baitaphish