ActiveMQ-cve-2026-42588-scanner-gui
【One-click VPS Exploitation (Recommended for users with a VPS)】
- Enter the VPS public IP and listening port (e.g., 9999)
- Enter the command to execute (e.g., touch /tmp/cve_pwned)
- Click [Generate VPS Command] → Click [Copy Command]
- SSH into the VPS, paste the command, and press Enter
- See Serving HTTP on 0.0.0.0:9999 indicating the service has started
- Return to the tool, click [Execute Exploit] to send the Payload
- Check the VPS terminal; if you see GET /evil.xml, the exploit was successful!
【DNSLog Verification (Simplest, no VPS required)】
- Click [Get DNSLog] to automatically obtain a domain
- Click [Execute Exploit] to send the Payload
- Visit http://www.dnslog.cn and click [Refresh] to check
- If you see a DNS query record, the vulnerability exists!
【Vulnerability Principle】
CVE-2026-42588: masterslave URI → ActiveMQ downloads malicious XML → Spring instantiates Bean → RCE
Affected versions: 5.x < 5.19.4, 6.0.0 ≤ 6.x < 6.2.3
