PatchSiren cyber security CVE debrief
CVE-2026-67593 Apache Software Foundation CVE debrief
CVE-2026-67593 is a critical vulnerability in Apache Artemis, allowing remote attackers to delete queues on the broker before or after authentication and authorization. This issue affects Apache Artemis versions 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis versions 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.
- Vendor
- Apache Software Foundation
- Product
- Apache Artemis
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-10
- Original CVE updated
- 2026-09-16
- Advisory published
- 2026-09-10
- Advisory updated
- 2026-09-16
Who should care
Defenders responsible for Apache Artemis and Apache ActiveMQ Artemis deployments should assess exposure and prioritize upgrading to version 2.57.0. This includes operators, platform administrators, vulnerability management teams, and security teams who manage these systems. They should verify their deployments against the affected versions and take appropriate remediation steps to prevent potential queue deletion and disruption to message processing and
Why it matters
CVE-2026-67593 is a critical vulnerability in Apache Artemis, allowing remote attackers to delete queues on the broker. Defenders should prioritize upgrading to version 2.57.0 to prevent queue deletion and potential disruption to message processing and queue-based applications. Affected versions require verification, and remediation priority is high for versions 2.50.0 through 2.56.0 and 1.0.0 through 2.44.0.
- Potential queue deletion before or after authentication and authorization
- Possible disruption to message processing and queue-based applications
- Requires verification of affected versions and inventory checks
- Remediation priority for versions 2.50.0 through 2.56.0 and 1.0.0 through 2.44.0
Technical summary
A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. The vulnerability allows for potential disruption to message processing and queue-based applications. Defenders should prioritize upgrading to version 2.57.0 to prevent queue deletion and potential disruption.
Defensive priority
Defenders should prioritize upgrading to version 2.57.0 to prevent queue deletion.
Recommended defensive actions
- Upgrade to version 2.57.0
- Review and update affected versions
- Monitor for potential queue deletion attempts
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD vulnerability detail page provide information on the vulnerability, its impact, and recommended actions. Evidence from these sources indicates that the vulnerability affects Apache Artemis versions 2.50.0 through 2.56.0 and Apache ActiveMQ Artemis versions 1.0.0 through 2.44.0. Defenders should verify their deployments against these versions and assess exposure. The Openwire RemoveSubscriptionInfo command can be crafted to delete queues on the Artemis broker before or after authentication and authorization, and
Sources and references
Verified primary and authoritative sources
-
CVE-2026-67593 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-67593
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-67593 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-67593
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://lists.apache.org/thread/zlglnsg8s5xv8n56d15dm5mf00h2d8xs
[email protected] - Mailing List, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.