Back to blog

// OSSeva Blog

Security

ActiveMQ Classic Vulnerabilities by Version: CVEs for 5.15 to 5.19 and 6.x

Matt Reynolds10 min read

The short answer

Two ActiveMQ Classic lines get security fixes today: 5.19.x, whose latest release is 5.19.11, and 6.3.x, whose latest is 6.3.2. The 6.2 line was marked inactive in September 2026 and its final release, 6.2.10, does not contain the fix for CVE-2026-74761. Every older line is out of support: 5.18 ended with 5.18.7 in March 2025, 5.16 and 5.17 had their last releases that same month, and 5.15 ended with 5.15.16 in October 2023. ActiveMQ has three CVEs in CISA's Known Exploited Vulnerabilities catalogue, CVE-2023-46604, CVE-2016-3088 and CVE-2026-34197, and the third of those has no fix for 5.18 or anything older.

Release lines and their last releases

Apache describes a Classic line as inactive once it has reached end of life and gets no further updates. Dates come from the ActiveMQ download page and endoflife.date.

LineFirst releaseLatest or final releaseStatus
6.3July 20266.3.2Active
6.2November 20256.2.10Inactive since September 2026
6.1March 20246.1.8 (October 2025)End of life December 2025
6.0November 20236.0.1 (November 2023)End of life March 2024
5.19March 20255.19.11Active
5.18March 20235.18.7 (March 2025)End of life March 2025
5.17March 20225.17.7 (March 2025)End of life April 2024
5.16June 20205.16.8 (March 2025)End of life March 2023
5.15June 20175.15.16 (October 2023)End of life March 2022

The March 2025 releases on 5.16, 5.17 and 5.18 shipped the fix for CVE-2025-27533 after those lines had already left support. Nothing has been released on them since.

The three ActiveMQ CVEs in the KEV catalogue

CVEIssueCVSSAdded to KEVFixed inLines with no fix
CVE-2023-46604Unauthenticated remote code execution through the OpenWire protocol marshaller9.8 (NVD); 10.0 (Apache)2 November 2023, known ransomware use5.15.16, 5.16.7, 5.17.6, 5.18.3; 6.0.0 and later were never affected5.14 and older
CVE-2016-3088The Fileserver web application allows file upload and execution over HTTP PUT and MOVE9.810 February 20225.14.0, which removed the Fileserver application5.0.0 to 5.13.x
CVE-2026-34197An authenticated user runs code through Jolokia MBean operations8.816 April 20265.19.4, 6.2.35.18 and older, 6.0, 6.1

CVE-2023-46604 is the most serious of the three. It needs no credentials, only network access to the OpenWire port, and CISA records it as used in ransomware campaigns. Apache also fixed it on 5.15, which had been out of support for more than a year. CVE-2026-34197 is a different case: it needs a login to the web console, and the console ships with admin and admin as its default credentials. NVD's 8.8 for it comes from CISA-ADP.

The 2026 fix releases

Apache's advisory list for Classic has more entries from 2026 than from any earlier year, most of them in Jolokia, the web console and the protocol codecs. Each wave shipped on 5.19 and on 6.2 or 6.3: the July wave on all three lines, and the September wave on 5.19 and 6.3 only. NVD month is when the CVE records were published.

NVD monthFixed inCVEs
April 20265.19.4, 6.2.3CVE-2026-34197, CVE-2026-33227
April 20265.19.4 and 6.2.4; 6.2.4 only for CVE-2026-40046CVE-2026-39304, CVE-2026-40046
April 20265.19.6, 6.2.5CVE-2026-40466, CVE-2026-41043, CVE-2026-41044
June 20265.19.7, 6.2.6CVE-2026-42253, CVE-2026-42588, CVE-2026-45505, CVE-2026-46605, CVE-2026-49157, CVE-2026-49270
June 20265.19.8, 6.2.7CVE-2026-49432, CVE-2026-49434, CVE-2026-49877, CVE-2026-50734, CVE-2026-50750, CVE-2026-52760, CVE-2026-53916, CVE-2026-53917, CVE-2026-54475
July 20265.19.9, 6.2.8, 6.3.0CVE-2026-59878, CVE-2026-61487
September 20265.19.11, 6.3.2CVE-2026-74761

Apart from CVE-2026-40046, which affects 6.x only, and CVE-2026-50750, every one of these lists 5.18 and older as affected, because the advisory gives the 5.x range as "before 5.19.x". CVE-2026-40046 exists because the fix for CVE-2025-66168, an MQTT length validation flaw, reached 5.19.2 but was missed on 6.x until 6.2.4. CVE-2026-50750 is the reverse case: a pre-authentication denial of service introduced by the fix for CVE-2026-49270, so only 5.19.7 and 6.2.6 are affected.

Notable ActiveMQ Classic CVEs by release line

CVSS is NVD's own score where NVD has analysed the record. For most 2026 ActiveMQ records NVD has not scored the CVE itself, and the figure is the CVSS 3.1 score CISA-ADP added; Apache's own ratings are important, moderate or low.

CVEIssueCVSS5.19 fix6.x fix5.18 and older
CVE-2026-40466Bypass of the CVE-2026-34197 fix through an HTTP discovery transport8.85.19.66.2.5Not patched
CVE-2026-41044Authenticated code execution through the DestinationView MBean exposed by Jolokia8.85.19.66.2.5Not patched
CVE-2026-45505Discovery wrapper URIs bypass the addNetworkConnector validation added for CVE-2026-341978.85.19.76.2.6Not patched
CVE-2026-49157Low-privilege web console users keep Jolokia broker management by default8.85.19.76.2.6Not patched
CVE-2026-42588Remote code execution through Jolokia addNetworkConnector8.15.19.76.2.6Not patched
CVE-2026-49877Low-privilege web console users can reach the admin pages by default8.15.19.86.2.7Not patched
CVE-2026-54475Another connection can consume from a connection's temporary destination7.55.19.86.2.7Not patched
CVE-2026-50734Pre-authentication memory allocation denial of service during OpenWire wire format negotiation7.55.19.86.2.7Not patched
CVE-2026-53917Unbounded memory allocation when unmarshalling OpenWire properties7.55.19.86.2.7Not patched
CVE-2026-49432A negative STOMP content-length lets an unauthenticated peer exhaust memory7.55.19.86.2.7Not patched
CVE-2026-39304TLS 1.3 KeyUpdate handling lets a peer drive the broker out of memory7.55.19.46.2.4Not patched
CVE-2026-74761An authenticated client spoofs another clientId when removing a durable subscription7.55.19.116.3.2; not in 6.2.10Not patched
CVE-2026-61487Authorization bypass through temporary composite destinations6.55.19.96.2.8, 6.3.0Not patched
CVE-2024-32114The Jolokia and REST APIs are unauthenticated in the default 6.x configuration8.8Not affected6.1.2Not affected
CVE-2025-27533Unchecked buffer length in OpenWire unmarshalling causes excessive memory allocation7.5Not affected6.1.65.16.8, 5.17.7, 5.18.7; 5.15 not patched
CVE-2022-41678Authenticated code execution through Jolokia8.8Not affectedNot affected5.16.6, 5.17.4; 5.18.0 ships the restricted Jolokia config

"Not patched" means the line is affected and no release on it carries the fix. Since April 2026 the Jolokia and network connector fixes have come in a chain, and two of them, CVE-2026-40466 and CVE-2026-45505, are bypasses of the fix for CVE-2026-34197. A broker that took 5.19.4 for the KEV-listed CVE-2026-34197 is still exposed to CVE-2026-40466, CVE-2026-45505 and CVE-2026-42588, so the release to aim for is the newest one, not the first that fixed the headline CVE.

What each line gets

6.3 and 5.19

These are the two lines Apache patches. Both carry every fix in the tables above, and 6.3.2 and 5.19.11 are the releases to run. 6.3 moves the bundled Spring to 7.0 and Jetty to 12.1, which matters most where the broker is embedded in a Spring application.

6.2

6.2 received every 2026 fix through 6.2.8 and then became inactive in September 2026. Its final release, 6.2.10, came out after the CVE-2026-74761 advisory without the fix.

6.1 and 6.0

6.1 reached end of life in December 2025 with 6.1.8, and 6.0 in March 2024 with 6.0.1. Apart from CVE-2026-50750, every 2026 CVE above affects both, including CVE-2026-34197. A 6.0.x broker also lacks the fix for CVE-2024-32114, so unless its configuration was changed by hand its Jolokia and REST APIs need no login.

5.18

5.18 reached end of life in March 2025 with 5.18.7. It has the fix for CVE-2023-46604 from 5.18.3 and for CVE-2025-27533 from 5.18.7, and none of the 2026 fixes. That leaves CVE-2026-34197, which is in the KEV catalogue, and the bypasses that followed. See ActiveMQ 5.18 end of life.

5.15, 5.16 and 5.17

These lines are fixed for CVE-2023-46604 only from 5.15.16, 5.16.7 and 5.17.6, so the first thing to confirm on any of them is the exact patch release. 5.16 and 5.17 also got the CVE-2025-27533 fix in March 2025. None has any fix released since.

5.14 and older

Anything before 5.14.0 still contains the Fileserver application behind CVE-2016-3088. It has been disabled by default since 5.12.0, so 5.11 and older expose it unless it was switched off by hand. These lines are also open to CVE-2023-46604, and 5.0 to 5.12 to the deserialization flaw CVE-2015-5254.

What to do on each line

  • 6.3 and 5.19. Stay on the newest patch release. Fixes in 2026 have arrived roughly monthly.
  • 6.2. Move to 6.3.2, allowing for the Spring 7.0 and Jetty 12.1 change.
  • 6.1 and 6.0. Move to 6.3.2, testing the same Spring and Jetty changes as a move from 6.2.
  • 5.18 and older. Move to 5.19.11 if your integrations allow it, or take patched builds for the line you run. In the meantime, change default web console credentials, restrict who can reach port 8161 and the Jolokia endpoint, and keep OpenWire on internal networks.

For estates deciding between staying on Classic and moving on, the Classic to Artemis migration guide covers the larger move.

Where OSSeva fits

OSSeva backports ActiveMQ Classic security fixes to 5.15, 5.16, 5.17 and 5.18 and ships them as signed builds for the line you already run, so a broker on 5.18.7 can close CVE-2026-34197 and the 2026 Jolokia fixes without a version jump. They are available now on the Patch, Assure and Operate tiers. Assure adds a broker audit and a costed path to Artemis or RabbitMQ, and Operate adds 24/7 broker monitoring with a 15-minute SLA and named JMS engineers. See ActiveMQ Classic extended support, ActiveMQ support and the ActiveMQ Classic end-of-life chart.

Tags

ActiveMQCVECVE-2023-46604CVE-2026-34197End of Life

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.