Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Chaining an Apache ActiveMQ RCE on a Fully Patched 6.2.5 (CVE-2026-34197)

Summary

Crowdfense demonstrates two Windows-specific bypasses that restore the CVE-2026-34197 Jolokia MBean RCE chain on ActiveMQ Classic 6.2.5. Apache ActiveMQ Classic 6.2.6 closes the demonstrated chain.

Why it matters

The research shows how parser mismatches and incomplete fixes can restore RCE on a nominally patched broker, making ActiveMQ Classic 6.2.6 the meaningful remediation point for this chain.
Vendor
Apache
Product
ActiveMQ Classic
Affected versions
Original ranges: < 5.19.5 and >= 6.0.0, < 6.2.3; demonstrated Windows fix-bypass chain affects 6.2.5 and is fixed in 6.2.6
CVSS
8.8
Published
Collected

original ↗

Related coverage

back