// OSSeva Blog
SecurityActiveMQ Classic Vulnerabilities by Version: CVEs for 5.15 to 5.19 and 6.x
The short answer
Two ActiveMQ Classic lines get security fixes today: 5.19.x, whose latest release is 5.19.11, and 6.3.x, whose latest is 6.3.2. The 6.2 line was marked inactive in September 2026 and its final release, 6.2.10, does not contain the fix for CVE-2026-74761. Every older line is out of support: 5.18 ended with 5.18.7 in March 2025, 5.16 and 5.17 had their last releases that same month, and 5.15 ended with 5.15.16 in October 2023. ActiveMQ has three CVEs in CISA's Known Exploited Vulnerabilities catalogue, CVE-2023-46604, CVE-2016-3088 and CVE-2026-34197, and the third of those has no fix for 5.18 or anything older.
Release lines and their last releases
Apache describes a Classic line as inactive once it has reached end of life and gets no further updates. Dates come from the ActiveMQ download page and endoflife.date.
| Line | First release | Latest or final release | Status |
|---|---|---|---|
| 6.3 | July 2026 | 6.3.2 | Active |
| 6.2 | November 2025 | 6.2.10 | Inactive since September 2026 |
| 6.1 | March 2024 | 6.1.8 (October 2025) | End of life December 2025 |
| 6.0 | November 2023 | 6.0.1 (November 2023) | End of life March 2024 |
| 5.19 | March 2025 | 5.19.11 | Active |
| 5.18 | March 2023 | 5.18.7 (March 2025) | End of life March 2025 |
| 5.17 | March 2022 | 5.17.7 (March 2025) | End of life April 2024 |
| 5.16 | June 2020 | 5.16.8 (March 2025) | End of life March 2023 |
| 5.15 | June 2017 | 5.15.16 (October 2023) | End of life March 2022 |
The March 2025 releases on 5.16, 5.17 and 5.18 shipped the fix for CVE-2025-27533 after those lines had already left support. Nothing has been released on them since.
The three ActiveMQ CVEs in the KEV catalogue
| CVE | Issue | CVSS | Added to KEV | Fixed in | Lines with no fix |
|---|---|---|---|---|---|
| CVE-2023-46604 | Unauthenticated remote code execution through the OpenWire protocol marshaller | 9.8 (NVD); 10.0 (Apache) | 2 November 2023, known ransomware use | 5.15.16, 5.16.7, 5.17.6, 5.18.3; 6.0.0 and later were never affected | 5.14 and older |
| CVE-2016-3088 | The Fileserver web application allows file upload and execution over HTTP PUT and MOVE | 9.8 | 10 February 2022 | 5.14.0, which removed the Fileserver application | 5.0.0 to 5.13.x |
| CVE-2026-34197 | An authenticated user runs code through Jolokia MBean operations | 8.8 | 16 April 2026 | 5.19.4, 6.2.3 | 5.18 and older, 6.0, 6.1 |
CVE-2023-46604 is the most serious of the three. It needs no credentials, only network access to the OpenWire port, and CISA records it as used in ransomware campaigns. Apache also fixed it on 5.15, which had been out of support for more than a year. CVE-2026-34197 is a different case: it needs a login to the web console, and the console ships with admin and admin as its default credentials. NVD's 8.8 for it comes from CISA-ADP.
The 2026 fix releases
Apache's advisory list for Classic has more entries from 2026 than from any earlier year, most of them in Jolokia, the web console and the protocol codecs. Each wave shipped on 5.19 and on 6.2 or 6.3: the July wave on all three lines, and the September wave on 5.19 and 6.3 only. NVD month is when the CVE records were published.
| NVD month | Fixed in | CVEs |
|---|---|---|
| April 2026 | 5.19.4, 6.2.3 | CVE-2026-34197, CVE-2026-33227 |
| April 2026 | 5.19.4 and 6.2.4; 6.2.4 only for CVE-2026-40046 | CVE-2026-39304, CVE-2026-40046 |
| April 2026 | 5.19.6, 6.2.5 | CVE-2026-40466, CVE-2026-41043, CVE-2026-41044 |
| June 2026 | 5.19.7, 6.2.6 | CVE-2026-42253, CVE-2026-42588, CVE-2026-45505, CVE-2026-46605, CVE-2026-49157, CVE-2026-49270 |
| June 2026 | 5.19.8, 6.2.7 | CVE-2026-49432, CVE-2026-49434, CVE-2026-49877, CVE-2026-50734, CVE-2026-50750, CVE-2026-52760, CVE-2026-53916, CVE-2026-53917, CVE-2026-54475 |
| July 2026 | 5.19.9, 6.2.8, 6.3.0 | CVE-2026-59878, CVE-2026-61487 |
| September 2026 | 5.19.11, 6.3.2 | CVE-2026-74761 |
Apart from CVE-2026-40046, which affects 6.x only, and CVE-2026-50750, every one of these lists 5.18 and older as affected, because the advisory gives the 5.x range as "before 5.19.x". CVE-2026-40046 exists because the fix for CVE-2025-66168, an MQTT length validation flaw, reached 5.19.2 but was missed on 6.x until 6.2.4. CVE-2026-50750 is the reverse case: a pre-authentication denial of service introduced by the fix for CVE-2026-49270, so only 5.19.7 and 6.2.6 are affected.
Notable ActiveMQ Classic CVEs by release line
CVSS is NVD's own score where NVD has analysed the record. For most 2026 ActiveMQ records NVD has not scored the CVE itself, and the figure is the CVSS 3.1 score CISA-ADP added; Apache's own ratings are important, moderate or low.
| CVE | Issue | CVSS | 5.19 fix | 6.x fix | 5.18 and older |
|---|---|---|---|---|---|
| CVE-2026-40466 | Bypass of the CVE-2026-34197 fix through an HTTP discovery transport | 8.8 | 5.19.6 | 6.2.5 | Not patched |
| CVE-2026-41044 | Authenticated code execution through the DestinationView MBean exposed by Jolokia | 8.8 | 5.19.6 | 6.2.5 | Not patched |
| CVE-2026-45505 | Discovery wrapper URIs bypass the addNetworkConnector validation added for CVE-2026-34197 | 8.8 | 5.19.7 | 6.2.6 | Not patched |
| CVE-2026-49157 | Low-privilege web console users keep Jolokia broker management by default | 8.8 | 5.19.7 | 6.2.6 | Not patched |
| CVE-2026-42588 | Remote code execution through Jolokia addNetworkConnector | 8.1 | 5.19.7 | 6.2.6 | Not patched |
| CVE-2026-49877 | Low-privilege web console users can reach the admin pages by default | 8.1 | 5.19.8 | 6.2.7 | Not patched |
| CVE-2026-54475 | Another connection can consume from a connection's temporary destination | 7.5 | 5.19.8 | 6.2.7 | Not patched |
| CVE-2026-50734 | Pre-authentication memory allocation denial of service during OpenWire wire format negotiation | 7.5 | 5.19.8 | 6.2.7 | Not patched |
| CVE-2026-53917 | Unbounded memory allocation when unmarshalling OpenWire properties | 7.5 | 5.19.8 | 6.2.7 | Not patched |
| CVE-2026-49432 | A negative STOMP content-length lets an unauthenticated peer exhaust memory | 7.5 | 5.19.8 | 6.2.7 | Not patched |
| CVE-2026-39304 | TLS 1.3 KeyUpdate handling lets a peer drive the broker out of memory | 7.5 | 5.19.4 | 6.2.4 | Not patched |
| CVE-2026-74761 | An authenticated client spoofs another clientId when removing a durable subscription | 7.5 | 5.19.11 | 6.3.2; not in 6.2.10 | Not patched |
| CVE-2026-61487 | Authorization bypass through temporary composite destinations | 6.5 | 5.19.9 | 6.2.8, 6.3.0 | Not patched |
| CVE-2024-32114 | The Jolokia and REST APIs are unauthenticated in the default 6.x configuration | 8.8 | Not affected | 6.1.2 | Not affected |
| CVE-2025-27533 | Unchecked buffer length in OpenWire unmarshalling causes excessive memory allocation | 7.5 | Not affected | 6.1.6 | 5.16.8, 5.17.7, 5.18.7; 5.15 not patched |
| CVE-2022-41678 | Authenticated code execution through Jolokia | 8.8 | Not affected | Not affected | 5.16.6, 5.17.4; 5.18.0 ships the restricted Jolokia config |
"Not patched" means the line is affected and no release on it carries the fix. Since April 2026 the Jolokia and network connector fixes have come in a chain, and two of them, CVE-2026-40466 and CVE-2026-45505, are bypasses of the fix for CVE-2026-34197. A broker that took 5.19.4 for the KEV-listed CVE-2026-34197 is still exposed to CVE-2026-40466, CVE-2026-45505 and CVE-2026-42588, so the release to aim for is the newest one, not the first that fixed the headline CVE.
What each line gets
6.3 and 5.19
These are the two lines Apache patches. Both carry every fix in the tables above, and 6.3.2 and 5.19.11 are the releases to run. 6.3 moves the bundled Spring to 7.0 and Jetty to 12.1, which matters most where the broker is embedded in a Spring application.
6.2
6.2 received every 2026 fix through 6.2.8 and then became inactive in September 2026. Its final release, 6.2.10, came out after the CVE-2026-74761 advisory without the fix.
6.1 and 6.0
6.1 reached end of life in December 2025 with 6.1.8, and 6.0 in March 2024 with 6.0.1. Apart from CVE-2026-50750, every 2026 CVE above affects both, including CVE-2026-34197. A 6.0.x broker also lacks the fix for CVE-2024-32114, so unless its configuration was changed by hand its Jolokia and REST APIs need no login.
5.18
5.18 reached end of life in March 2025 with 5.18.7. It has the fix for CVE-2023-46604 from 5.18.3 and for CVE-2025-27533 from 5.18.7, and none of the 2026 fixes. That leaves CVE-2026-34197, which is in the KEV catalogue, and the bypasses that followed. See ActiveMQ 5.18 end of life.
5.15, 5.16 and 5.17
These lines are fixed for CVE-2023-46604 only from 5.15.16, 5.16.7 and 5.17.6, so the first thing to confirm on any of them is the exact patch release. 5.16 and 5.17 also got the CVE-2025-27533 fix in March 2025. None has any fix released since.
5.14 and older
Anything before 5.14.0 still contains the Fileserver application behind CVE-2016-3088. It has been disabled by default since 5.12.0, so 5.11 and older expose it unless it was switched off by hand. These lines are also open to CVE-2023-46604, and 5.0 to 5.12 to the deserialization flaw CVE-2015-5254.
What to do on each line
- 6.3 and 5.19. Stay on the newest patch release. Fixes in 2026 have arrived roughly monthly.
- 6.2. Move to 6.3.2, allowing for the Spring 7.0 and Jetty 12.1 change.
- 6.1 and 6.0. Move to 6.3.2, testing the same Spring and Jetty changes as a move from 6.2.
- 5.18 and older. Move to 5.19.11 if your integrations allow it, or take patched builds for the line you run. In the meantime, change default web console credentials, restrict who can reach port 8161 and the Jolokia endpoint, and keep OpenWire on internal networks.
For estates deciding between staying on Classic and moving on, the Classic to Artemis migration guide covers the larger move.
Where OSSeva fits
OSSeva backports ActiveMQ Classic security fixes to 5.15, 5.16, 5.17 and 5.18 and ships them as signed builds for the line you already run, so a broker on 5.18.7 can close CVE-2026-34197 and the 2026 Jolokia fixes without a version jump. They are available now on the Patch, Assure and Operate tiers. Assure adds a broker audit and a costed path to Artemis or RabbitMQ, and Operate adds 24/7 broker monitoring with a 15-minute SLA and named JMS engineers. See ActiveMQ Classic extended support, ActiveMQ support and the ActiveMQ Classic end-of-life chart.
Tags
Related articles
Redis Vulnerabilities by Version: CVEs for Redis 6.2, 7.0, 7.2, 7.4 and 8.x
October 5, 2026SecurityErlang/OTP Vulnerabilities by Version: CVEs for OTP 24 to 29 and the RabbitMQ Releases That Pin Them
October 5, 2026SecurityApache Solr Vulnerabilities by Version: CVEs for Solr 7, 8, 9 and 10
October 5, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.