Red Hot Cyber
Cybersecurity is about sharing. Recognize the risk, combat it, share your experiences, and encourage others to do better than you.
Cybersecurity is about sharing. Recognize the risk,
combat it, share your experiences, and encourage others
to do better than you.
UtiliaCS 320x100
Redhotcyber Banner Sito 970x120px Uscita 101125
Apache ActiveMQ NMS AMQP Vulnerability in 9.8: Urgent Update Required

Apache ActiveMQ NMS AMQP Vulnerability in 9.8: Urgent Update Required

17 October 2025 16:05

An untrusted data deserialization vulnerability has been identified in the Apache ActiveMQ NMS AMQP client, exposing systems to potential attacks from malicious servers.
The flaw, tracked as CVE-2025-54539, has a score of 9.8 out of 10, and affects all versions up to and including 2.3.0 when connections are established to untrusted AMQP servers.

According to security experts at Endor Labs , who reported the flaw, a suitably modified remote server can exploit the client’s unconstrained deserialization logic to send manipulated responses, potentially allowing arbitrary code execution on the victim’s system.

A security mechanism based on allow/deny lists was already introduced in version 2.1.0 to limit deserialization. However, subsequent analyses showed that this protection could be bypassed under certain circumstances , thus maintaining the risk of compromise.

In parallel to the vulnerability, the Apache ActiveMQ development team announced that, in line with Microsoft’s decision to deprecate binary serialization in .NET 9 , they are evaluating whether to completely remove support for .NET binary serialization in future versions of the NMS API.

Users are strongly advised to update the client to version 2.4.0 or later , which resolves the issue.

Additionally, all projects relying on NMS-AMQP should plan a migration from .NET binary serialization as part of a broader long-term security hardening strategy.

Follow us on Google News to receive daily updates on cybersecurity. Contact us if you would like to report news, insights or content for publication.

Cropped RHC 3d Transp2 1766828557 300x300
The editorial staff of Red Hot Cyber is composed of IT and cybersecurity professionals, supported by a network of qualified sources who also operate confidentially. The team works daily to analyze, verify, and publish news, insights, and reports on cybersecurity, technology, and digital threats, with a particular focus on the accuracy of information and the protection of sources. The information published is derived from direct research, field experience, and exclusive contributions from national and international operational contexts.