Stay tuned with SecureLayer7 Announcements

May 19, 2026

CVE-2025-54539: Apache ActiveMQ NMS AMQP Deserialization Policy Bypass to RCE

A deserialization filter is only as good as its checks. CVE-2025-54539 is a logic bug in Apache.NMS.AMQP’s NmsDefaultDeserializationPolicy where the policy’s IsTrustedType() method treats a null […]