Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ActiveMQ-cve-2026-42588-scanner-gui — GUI-based scanner and exploit tool for CVE-2026-42588 (ActiveMQ RCE). Supports VPS payload delivery and DNSLog-based vulnerability verification with automated XML injection. | Kitploit
Tools/GitHubGitHub/strivepan/activemq-cve-2026-42588-scanner-gui
Vulnerability ScannersPayload GenerationExploitationWeb Application ExploitationCommand and ControlRemote Access Tool
GitHubstrivepan/activemq-cve-2026-42588-scanner-gui

ActiveMQ-cve-2026-42588-scanner-gui

GUI-based scanner and exploit tool for CVE-2026-42588 (ActiveMQ RCE). Supports VPS payload delivery and DNSLog-based vulnerability verification with automated XML injection.

View Repository
1013 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

ActiveMQ-cve-2026-42588-scanner-gui

【One-click VPS Exploitation (Recommended for users with a VPS)】

  1. Enter the VPS public IP and listening port (e.g., 9999)
  2. Enter the command to execute (e.g., touch /tmp/cve_pwned)
  3. Click [Generate VPS Command] → Click [Copy Command]
  4. SSH into the VPS, paste the command, and press Enter
  5. See Serving HTTP on 0.0.0.0:9999 indicating the service has started
  6. Return to the tool, click [Execute Exploit] to send the Payload
  7. Check the VPS terminal; if you see GET /evil.xml, the exploit was successful!

【DNSLog Verification (Simplest, no VPS required)】

  1. Click [Get DNSLog] to automatically obtain a domain
  2. Click [Execute Exploit] to send the Payload
  3. Visit http://www.dnslog.cn and click [Refresh] to check
  4. If you see a DNS query record, the vulnerability exists!

【Vulnerability Principle】 CVE-2026-42588: masterslave URI → ActiveMQ downloads malicious XML → Spring instantiates Bean → RCE Affected versions: 5.x < 5.19.4, 6.0.0 ≤ 6.x < 6.2.3

ActiveMQ ActiveMQ_RCE
Download Tool