The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
http://www.zerodayinitiative.com/advisories/ZDI-16-357
https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/
https://research.checkpoint.com/speakup-a-new-undetected-backdoor-linux-trojan/