THE Apache Software Foundation has addressed two vulnerabilities in Apache ActiveMQ: one allows low-privilege users to bypass write permissions on protected queues (CVE-2026-61487), and the other enables remote attackers to crash AMQP connections, potentially causing service denial (CVE-2026-59878). Both vulnerabilities impact ActiveMQ Broker and its associated packages, with affected versions running prior to 5.19.9 and between 6.0.0 to 6.2.7. Apache recommends upgrading to versions 5.19.9, 6.2.8, or 6.3.0. Users are advised to restrict access until patches are applied, as no proof-of-concept or exploitation has been reported.
Apache ActiveMQ Patches Authorization Bypass and DoS Flaws
CyberSIXT Evidence Panel
Article by CyberSIXT