End of life

Apache ActiveMQ Classic 5.18 end of life

Apache ActiveMQ Classic 5.18 reached end of life in March 2025. The Apache ActiveMQ project marks the 5.18.x line as inactive, and 5.18.7 was the last release. Security fixes now ship only on 5.19 and 6.x, which means 5.18 brokers have no upstream fix for CVE-2026-34197, a Jolokia remote code execution flaw on CISA's exploited list.

End of life
March 2025
Released
Mar 2023
Final release
5.18.7
Successor
ActiveMQ Classic 5.19 or 6.x, or ActiveMQ Artemis

Date published by Apache ActiveMQ Classic download page and endoflife.date. We do not publish a lifecycle date we cannot source.

What actually stops on March 2025

  • Releases on the 5.18.x line. 5.18.7 was the last.
  • Security fixes for the broker, the web console and the bundled Jolokia endpoint. CVE-2026-34197 was fixed in 5.19.4 and 6.2.3 only.
  • Dependency updates for the libraries 5.18 bundles, including Spring 5 and Jetty.

What actually breaks in the upgrade

5.19 is a short hop, 6.x is not

Apache ActiveMQ 5.19 stays on the javax.jms API, so moving from 5.18 to 5.19 is a routine broker upgrade and brings the current security fixes. Apache ActiveMQ 6.x implements Jakarta Messaging 3.1 on the jakarta.jms API, so every client application built against javax.jms has to move too.

Artemis is a re-platform

ActiveMQ Artemis is the other ActiveMQ broker, with a different storage engine and configuration model. It accepts OpenWire clients, which eases the move, but broker configuration, persistence and operational tooling all change.

Amazon MQ has no 6.x

Amazon MQ for ActiveMQ supports 5.18 and 5.19 only. Managed brokers can move to 5.19, but there is no managed path to Jakarta Messaging.

Your options, costed honestly

Including the ones that do not involve buying anything from us.

OptionWhat it isEffortCostOur view
Upgrade to 5.19Same javax.jms API, current security fixes.DaysEngineering timeThe fastest way to close CVE-2026-34197. Plan the next move while you are there.
Upgrade to 6.xJakarta Messaging on the Classic broker.Weeks to quartersClient application changesRight when applications are moving to Jakarta EE anyway.
Migrate to ArtemisThe broker the ActiveMQ project is investing in.QuartersRe-platformWorth it for estates that will run brokers for years.
Extended support on 5.18Backported fixes for the 5.18 line.DaysSubscriptionFor brokers pinned by a vendor product or a change freeze.

What OSSeva does for Apache ActiveMQ Classic 5.18

OSSeva patches this line

OSSeva backports security fixes to ActiveMQ Classic 5.15 to 5.18, delivered as signed builds, and runs 6.x and Artemis migrations when you are ready to move.

Apache ActiveMQ Classic extended support

What your auditor will say

PCI DSS 4.0

Requirement 6.3.3. A broker carrying cardholder data with a KEV-listed flaw and no vendor fix is a finding.

CISA BOD 22-01

US federal agencies must remediate KEV-listed vulnerabilities, including CVE-2026-34197 and CVE-2023-46604, by the catalog deadline.

Compliance library

Apache ActiveMQ Classic 5.18: common questions

When did ActiveMQ 5.18 reach end of life?

In March 2025. Apache publishes no formal end date, but marks 5.18.x inactive; endoflife.date records 11 March 2025, and 5.18.7 on 19 March 2025 was the last release.

Which Apache ActiveMQ Classic versions are currently supported?

The 5.19 line and the 6.x line receive releases. Check the ActiveMQ download page for the current minor versions.

Is ActiveMQ 5.18 affected by CVE-2026-34197?

Yes. It affects ActiveMQ Classic before 5.19.4 and 6.x before 6.2.3. An authenticated attacker who can reach the Jolokia endpoint can execute code. It has been on CISA's Known Exploited Vulnerabilities catalog since 16 April 2026.

Can I still get support for ActiveMQ 5.18?

Yes, from third parties. OSSeva provides patched 5.18 builds and migration support.

Still running Apache ActiveMQ Classic 5.18?

Tell us the versions and the estate size. We will tell you honestly whether to upgrade or to buy cover — and we say 'upgrade' more often than you would expect.