Back to all use cases
ActiveMQ ClassicLogistics
A known-exploited flaw with no 5.18 fix
A logistics company runs ActiveMQ Classic 5.18 inside a warehouse management product. CVE-2026-34197 is on CISA's exploited list and fixed only in 5.19.4 and 6.2.3.
Challenge
The vendor product certifies 5.18 only and will not support a broker upgrade until its next major release, so the security team cannot simply apply the upstream fix.
Environment
ActiveMQ Classic 5.18 brokers embedded in a vendor application, Jolokia and web console reachable on the internal network.
Approach
OSSeva backports the fix to 5.18, reviews which brokers expose Jolokia and the web console, and plans the eventual move to 6.x or Artemis with the vendor's roadmap.
What this delivers
The exploited flaw closed on the certified version, with an exposure review the security team can show auditors.