CVE-2025-54539PoC(apache / activemq_nms_amqp)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch apache activemq_nms_amqp systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all versions of Apache ActiveMQ NMS AMQP up to and including 2.3.0, when establishing connections to untrusted AMQP servers. Malicious servers could exploit unbounded deserialization logic present in the client to craft responses that may lead to arbitrary code execution on the client side. Although version 2.1.0 introduced a mechanism to restrict deserialization via allow/deny lists, the protection was found to be bypassable under certain conditions. In line with Microsoft’s deprecation of binary serialization in .NET 9, the project is evaluating the removal of .NET binary serialization support from the NMS API entirely in future releases. Mitigation and Recommendations: Users are strongly encouraged to upgrade to version 2.4.0 or later, which resolves the issue. Additionally, projects depending on NMS-AMQP should migrate away from .NET binary serialization as part of a long-term hardening strategy.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • activemq_nms_amqp

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-20); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
activemq_nms_amqp

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-19: 1Mentions · 2026-05-20: 2Mentions · 2026-06-01: 1PoC Mentioned / Linked · 2026-05-19: 1PoC Mentioned / Linked · 2026-05-20: 1PoC Mentioned / Linked · 2026-06-01: 1Patch / Workaround · 2026-05-20: 1Technical Details · 2026-05-19: 1Technical Details · 2026-05-20: 2Technical Details · 2026-06-01: 105-1905-2006-01
Signal classification3 categories
PoC
250.0%
Disclosure
125.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-191
PoC1
2026-05-202
Disclosure1General1
2026-06-011
PoC1
Full discourse4 posts
  • Nicolas Krassas@Dinosn
    PoC

    CVE-2025-54539: Apache ActiveMQ NMS AMQP Deserialization Policy Bypass to RCE https://blog.securelayer7.net/cve-2025-54539-apache-nms-amqp-rce/

    Post summary

    The referenced blog post details CVE‑2025‑54539, a deserialization policy bypass in Apache ActiveMQ NMS AMQP that leads to remote code execution, and provides a proof‑of‑concept illustrating the exploit.

    115044145.9K
    158.6K followersView on X
  • ✪ 𝕱𝖆𝖍𝖆𝖉@fad_777
    Disclosure

    ثغرة جديدة في Apache ActiveMQ NMS AMQP تتيح تجاوز سياسات Deserialization والوصول لتنفيذ أوامر عن بُعد RCE. هذا النوع من الثغرات يوسع سطح الهجوم على بيئات الرسائل الحرجة ويتطلب تحديثات عاجلة وضبطًا دقيقًا لسياسات الأمان. CVE-2025-54539 exposes a deserialization policy bypass in Apache ActiveMQ NMS AMQP that can lead to remote code execution. Secure messaging stacks depend on strict deserialization controls, so timely patching and configuration hardening are critical to reducing exposure. https://blog.securelayer7.net/cve-2025-54539-apache-nms-amqp-rce/ #CVE202554539 #ApacheActiveMQ #AppSec

    Post summary

    The notice announces a newly disclosed CVE-2025-54539 in Apache ActiveMQ NMS AMQP, details a deserialization-bypass RCE vulnerability, and urges timely patching and configuration hardening.

    00010994
    67 followersView on X
  • dbugs@ptdbugs
    PoC

    ⚡️ Remote Code Execution in Apache NMS AMQP: CVE-2025-54539 Analysis PT ID: PT-2025-42438 The article examines the vulnerability CVE-2025-54539 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2025-54539), which allows remote code execution through unsafe deserialization in the Apache ActiveMQ .NET client library. A flaw in type validation causes malicious objects to be treated as trusted. The author demonstrates how a specially crafted AMQP message can trigger code execution on the client side. As a result, an attacker can compromise systems processing messages without direct access to the server. 📎 Article: https://blog.securelayer7.net/cve-2025-54539-apache-nms-amqp-rce/ #dbugs_attacks

    Post summary

    The article discloses CVE‑2025‑54539, explaining a remote code execution flaw in Apache ActiveMQ .NET due to unsafe deserialization, and demonstrates a PoC using crafted AMQP messages.

    00000136
    1.3K followersView on X
  • VulnTracker@vuln_tracker
    General

    @Dinosn Apache ActiveMQ thought its deserialization policy would save it. CVE-2025-54539 bypasses it entirely via AMQP - straight to RCE. ActiveMQ is the backbone of countless enterprise message brokers. If you're running NMS, this is not theoretical. http://vulntracker.io

    Post summary

    The tweet highlights that CVE-2025-54539 in Apache ActiveMQ enables remote code execution over AMQP, bypassing the broker’s deserialization policy, and signals a real‑world threat without providing mitigation or exploit details.

    000001.0K
    653 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheactivemq_nms_amqp---

Explore more