Vulnerability record

CVE-2026-94591

Exploitation: No known exploitation

Patch status

No official fix confirmed yet

Until a fix ships, follow the vendor's mitigations, limit exposure of affected systems, and watch this record for a patch.

Intelligence timeline

Developments from the last 30 days, newest first.

No developments recorded for CVE-2026-94591 in the last 30 days.

Coverage

Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

Armatura LLC Armatura One

Why it matters

CISA lists this as exploited in the wild and known to be used in ransomware campaigns. Unpatched ActiveMQ systems are exposed to active attacks now.

Act now

Treat this as an emergency.