Apache ActiveMQ Classic 6.1 end of life
Apache ActiveMQ Classic 6.1 left the project's current releases on 2 December 2025, and the download page now lists it as inactive. The last release was 6.1.8, on 19 October 2025. No 6.1 release fixes CVE-2026-34197, a Jolokia code execution flaw on CISA's exploited list. Moving to 6.3 keeps the same jakarta.jms API and Java 17 baseline.
- End of life
- 2 December 2025
- Released
- Mar 2024
- Final release
- 6.1.8 (19 October 2025)
- Successor
- ActiveMQ Classic 6.3
Date published by Apache ActiveMQ Classic download page. We do not publish a lifecycle date we cannot source.
Last reviewed
What actually stops on 2 December 2025
- Releases on the 6.1.x line. 6.1.8 was the last.
- Security fixes. CVE-2026-34197 was fixed in 6.2.3 and CVE-2026-74761 in 6.3.2, with no 6.1 release for either.
- A supported 6.x line other than 6.3. The 6.2.x line is inactive too, with 6.2.10 as its last release.
What actually breaks in the upgrade
6.1 to 6.3 is a broker upgrade
ActiveMQ 6.1 and 6.3 both implement Jakarta Messaging on the jakarta.jms API and need Java 17, so clients built for 6.1 keep working. Test the bundled Jetty and Spring versions against any web console customisation or embedded broker configuration.
Skip 6.2
6.2.x is also inactive. Moving to it would close CVE-2026-34197 but not CVE-2026-74761, and would leave the broker on an unmaintained line again.
Lock down Jolokia in the meantime
CVE-2026-34197 needs an authenticated user who can reach /api/jolokia/ on the web console. Restricting network access to the console and tightening its credentials reduces exposure, but does not fix the flaw.
Your options, costed honestly
Including the ones that do not involve buying anything from us.
| Option | What it is | Effort | Cost | Our view |
|---|---|---|---|---|
| Upgrade to 6.3 | Same API and Java baseline, current security fixes. | Days | Engineering time | The obvious move, and the only active 6.x line. |
| Migrate to Artemis | A different broker that accepts OpenWire clients. | Quarters | Re-platform | Worth it for estates that will run brokers for years. |
| OSSeva patched builds on 6.1 | Signed 6.1 builds with security fixes backported. | Days | Subscription | For brokers embedded in a product that pins 6.1. |
| Stay unpatched | No releases since October 2025. | None | Zero now | Leaves a KEV-listed flaw open. |
What OSSeva does for Apache ActiveMQ Classic 6.1
OSSeva patches this line
ActiveMQ Classic 6.x is in OSSeva's ActiveMQ coverage on the Patch, Assure and Operate tiers, and OSSeva backports security fixes to 6.1 as signed builds. OSSeva engineers also run the move to 6.3 or Artemis.
Apache ActiveMQ Classic extended supportWhat your auditor will say
Every system component in the cardholder data environment needs its applicable security patches. A component with no upstream fix supply needs a patched source or a documented compensating control.
Auditors ask for evidence that production systems receive security fixes. A version past end of life fails that test unless another supplier ships the fixes and can show which CVEs they close.
US federal agencies must remediate KEV-listed vulnerabilities by the catalogue deadline. CVE-2026-34197 is listed and has no 6.1 fix.
Apache ActiveMQ Classic 6.1: common questions
When did ActiveMQ 6.1 reach end of life?
The project removed 6.1.x from its current releases on 2 December 2025 and now lists it as inactive. The last release was 6.1.8, on 19 October 2025.
Is ActiveMQ 6.1 affected by CVE-2026-34197?
Yes. It affects 6.x before 6.2.3, which includes every 6.1 release. It has been on CISA's Known Exploited Vulnerabilities catalogue since 16 April 2026.
Which ActiveMQ 6 version should I upgrade to?
6.3. The download page lists 6.2.x as inactive as well, and CVE-2026-74761 is fixed in 6.3.2.
Can I get security patches for ActiveMQ 6.1?
Yes. OSSeva ships patched, signed 6.1 builds on the Patch, Assure and Operate tiers.
Still running Apache ActiveMQ Classic 6.1?
Tell us the versions and the estate size. We will tell you honestly whether to upgrade or to buy cover — and we say 'upgrade' more often than you would expect.