The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitrary files via an HTTP PUT followed by an HTTP MOVE request.
http://www.zerodayinitiative.com/advisories/ZDI-16-357
https://horizon3.ai/attack-research/disclosures/cve-2026-34197-activemq-rce-jolokia/
https://research.checkpoint.com/speakup-a-new-undetected-backdoor-linux-trojan/
https://github.com/Catherines77/ActiveMQ-EXPtools
https://github.com/HeArtE4t3r/CVE-2016-3088
https://github.com/Roronoawjd/CVEs
https://github.com/advisories/GHSA-rxqh-fc23-gxp2
https://github.com/YutuSec/ActiveMQ_Crack
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2016-3088
http://activemq.apache.org/security-advisories.data/CVE-2016-3088-announcement.txt