Artemis
Vendor:
First CVE: Sep 27, 2016 · Active for 9 years
15
Total CVEs
More Total CVEs than 92% of tracked products
1.9
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Artemis over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 27, 2016
9 years ago
Most Recent CVE
May 28, 2026
57 days ago
CVE Severity & Scoring
Artemis15 CVEs
53%
40%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (6.7%)
Network14 (93.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (86.7%)
Unknown0 (0.0%)
Required2 (13.3%)
Privileges Required
Low6 (40.0%)
High1 (6.7%)
None8 (53.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27446CRITICAL Missing Authentication for Critical Function (CWE-306) vulnerability in Apache Artemis, Apache ActiveMQ Artemis. An unauthenticated remote attacker can use the Core protocol to for | Mar 4, 2026 | 9.8 | 42 | NO | NO |
CVE-2023-50780HIGH Apache ActiveMQ Artemis allows access to diagnostic information and controls through MBeans, which are also exposed through the authenticated Jolokia endpoint. Before version 2.29. | Oct 14, 2024 | 8.8 | 29 | NO | NO |
CVE-2021-26117HIGH The optional ActiveMQ LDAP login module can be configured to use anonymous access to the LDAP server. In this case, for Apache ActiveMQ Artemis prior to version 2.16.0 and Apache A | Jan 27, 2021 | 7.5 | 29 | NO | NO |
CVE-2016-4978HIGH The getObject method of the javax.jms.ObjectMessage class in the (1) JMS Core client, (2) Artemis broker, and (3) Artemis REST component in Apache ActiveMQ Artemis before 1.4.0 mig | Sep 27, 2016 | 7.2 | 27 | NO | NO |
CVE-2021-26118HIGH While investigating ARTEMIS-2964 it was found that the creation of advisory messages in the OpenWire protocol head of Apache ActiveMQ Artemis 2.15.0 bypassed policy based access co | Jan 27, 2021 | 7.5 | 26 | NO | NO |
CVE-2022-23913HIGH In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumption of memory. | Feb 4, 2022 | 7.5 | 25 | NO | NO |
CVE-2017-12174HIGH It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroups discovery a huge byte array is created when receiving an unexpected multicast | Mar 7, 2018 | 7.5 | 23 | NO | NO |
CVE-2022-35278MEDIUM In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an add | Aug 23, 2022 | 6.1 | 22 | NO | NO |
CVE-2026-40914MEDIUM A vulnerability exists in Apache Artemis whereby an application using the STOMP protocol with security credentials that grant either the consume or send permission on an address ca | May 28, 2026 | 4.3 | 21 | NO | NO |
CVE-2021-4040MEDIUM A flaw was found in AMQ Broker. This issue can cause a partial interruption to the availability of AMQ Broker via an Out of memory (OOM) condition. This flaw allows an attacker to | Aug 24, 2022 | 5.3 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (15 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (15 CVEs).
Media Mentions
Signals from CVEs in this product scope (15 CVEs).
Top CNAs Publishing CVEs For Artemis
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.50.0 | 1 | 9.8 | 10.6% | 0 | 0 |
| 2.15.0 | 1 | 7.5 | 4.0% | 0 | 0 |