live wire
▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel▸JAVA · Quarkus 4.0.0.Beta1 moves to Java 21, adds HTTP/3 and starts extension migration (Oct. 1)Quarkus▸SECURITY · X41 shows shared /dev/shm can turn Envoy hot restart into cross-container lateral movementX41 D-Sec▸DATA · AWS and Red Hat map Confluent Platform on ROSA with HCP, CFK and OpenShift security controlsAWS IBM & Red Hat▸API · Red Hat resolves intermittent 3scale API Manager latencyRed Hat Status▸AI · IBM shows Maximo workflows exposed as approval-gated MCP tools on OpenShiftIBM Community▸AI · vLLM adds day-zero NVIDIA Vera Rubin support and reports 7.8× per-GPU throughputvLLM▸INTEGRATION · Apache Camel 4.23 makes Kamelets visible to AI tooling and validationApache Camel▸SECURITY · OpenShift 4.14.75 fixes five CVEs, including two SQLite code-execution flawsRed Hat Customer Portal▸SUPPLY CHAIN · Red Hat maps CRA-ready open source practices as EU reporting rules take effectRed Hat Blog▸AI · Red Hat AI Inference on IBM Cloud adds an OpenAI-compatible Embeddings APIIBM Cloud▸API · Red Hat investigates degraded 3scale API Management SaaS APIsRed Hat Status▸PLATFORM · Red Hat and Cloudera validate a 100-VM analytics stack on OpenShift VirtualizationRed Hat Blog▸DEVELOPER HUB · Red Hat maps a four-zone, quota-aware Dev Spaces architectureRed Hat Developer▸INTEGRATION · Camel 4.23 teaches agent tools to discover and validate KameletsApache Camel
upstreambeat.ai
newsDATA

AMQ Broker 7.13.6 backports the Artemis security fixes to the 7.13 stream

The Important-rated update gives 7.13 operators fixes for unauthenticated queue actions, session hijacking and cluster credential exposure without moving to 7.14.

Two broker update packages side by side, showing backported security fixes.
AI-generated illustration
By The News Desk· Sep 12, 2026the quick take — two AI hosts go live when you do

Red Hat has released AMQ Broker 7.13.6 as an Important-rated security and maintenance update, giving operators on the 7.13 stream a supported route to the broker-level fixes that also appeared in 7.14.1. The 7.13.6 advisory includes security fixes, bug fixes and enhancements; it does not require a move to the newer 7.14 stream.

What the backport changes

The most consequential fixes are in Apache ActiveMQ Artemis itself. Red Hat lists:

  • CVE-2026-49362, unauthenticated queue creation through the Artemis core protocol;
  • CVE-2026-57967, session hijacking caused by missing authentication;
  • CVE-2026-67593, pre-authentication deletion of arbitrary durable queues through OpenWire;
  • CVE-2026-49364, disclosure of the broker cluster password through JGroups spoofing;
  • CVE-2026-49363, pre-authentication topology disclosure; and
  • CVE-2026-57822, unsafe deserialization on the Artemis management address.

The update also carries fixes across the surrounding broker stack, including a Jolokia JMX-HTTP bridge code-execution flaw, Jackson Databind code-execution paths, Jetty digest-authentication bypass, Netty request smuggling and several denial-of-service conditions in STOMP, MQTT, HTTP, WebSocket and Qpid Proton-J processing.

The 7.13.6 and 7.14.1 advisories substantially overlap, but they are not identical component manifests. The decision is therefore stream-based: install the update built for the AMQ Broker line already in production rather than treating 7.14.1 as a prerequisite.

Who should prioritize it

Teams exposing the core protocol or OpenWire have direct unauthenticated broker-state risks in the fixed set. Clustered brokers should also account for the JGroups credential-disclosure issue, while deployments exposing management, STOMP or MQTT endpoints inherit additional relevant fixes.

Red Hat rates the update Important, not Critical, and the advisory does not claim exploitation in the wild. Even so, unauthenticated queue creation, durable-queue deletion and session hijacking can affect broker integrity and availability, so this is more than routine dependency churn.

Upgrade and verify

Red Hat instructs operators to back up the existing installation, including applications, configuration files, databases and database settings, before applying 7.13.6. The update download requires Customer Portal access.

After upgrading through the supported 7.13 channel, verify the broker version on every node, then retest authentication and authorization for each enabled protocol. Clustered deployments should confirm topology formation and message replication after rolling nodes. Finally, exercise queue creation and deletion with both authorized and unauthenticated clients, and check that existing durable subscriptions and store-and-forward queues remain intact.

The release also fixes reported 7.13 defects involving message loss after a graceful clustered-node restart under high load, an unresponsive Prometheus metrics endpoint, MQTT address deletion, and HTTP-tunneling reply starvation. Those fixes make post-upgrade checks of clustering, metrics and protocol-specific traffic part of the same maintenance window.

Filed by The News Desk. Corrections: desk@upstreambeat.ai · Our standards →

comments · 0

    Comments are moderated before they appear. Your email is used once to confirm it is you — never shown, never sold. Corrections and questions get an answer from the desk when we have one.