CISA tells feds to patch 13-year-old Apache ActiveMQ bug under active attack
2026-04-17T19:23:58Z•b2a223b929796a85a20656860d035e019ae2a1bd8d6de49b987257d2f24d073e
AI-assisted vulnerability discoveryApache ActiveMQCISAExcelFortinetGitHub ActionsKEVMicrosoftactive exploitationdata breachpatchingprompt injectionransomwareresurrected vulnerabilitiessandboxsocial engineeringvulnerabilityzero-day
What happened
CISA has ordered US federal agencies to urgently patch a 13‑year‑old Apache ActiveMQ vulnerability that is being actively exploited and added the flaw to its Known Exploited Vulnerabilities (KEV) list. The same feed highlights multiple concurrent high‑risk issues: a 17‑year‑old Microsoft Excel flaw under exploitation, several resurrected Microsoft vulnerabilities being used by attackers, two critical Fortinet sandbox bugs (auth bypass/remote command execution), and continuing data‑exfiltration incidents and social‑engineering campaigns targeting macOS and open‑source developers. The reporting也
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- b2a223b929796a85a20656860d035e019ae2a1bd8d6de49b987257d2f24d073e
- Enrichment time
- 2026-04-17T19:23:58Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.