CISA tells feds to patch 13-year-old Apache ActiveMQ bug under active attack

2026-04-17T19:23:58Zb2a223b929796a85a20656860d035e019ae2a1bd8d6de49b987257d2f24d073e
AI-assisted vulnerability discoveryApache ActiveMQCISAExcelFortinetGitHub ActionsKEVMicrosoftactive exploitationdata breachpatchingprompt injectionransomwareresurrected vulnerabilitiessandboxsocial engineeringvulnerabilityzero-day

What happened

CISA has ordered US federal agencies to urgently patch a 13‑year‑old Apache ActiveMQ vulnerability that is being actively exploited and added the flaw to its Known Exploited Vulnerabilities (KEV) list. The same feed highlights multiple concurrent high‑risk issues: a 17‑year‑old Microsoft Excel flaw under exploitation, several resurrected Microsoft vulnerabilities being used by attackers, two critical Fortinet sandbox bugs (auth bypass/remote command execution), and continuing data‑exfiltration incidents and social‑engineering campaigns targeting macOS and open‑source developers. The reporting也

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
b2a223b929796a85a20656860d035e019ae2a1bd8d6de49b987257d2f24d073e
Enrichment time
2026-04-17T19:23:58Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.