CVE-2023-32315Active Exploitation(igniterealtime / openfire)

MEDIUMCVSS 7.5 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for igniterealtime openfire systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Openfire is an XMPP server licensed under the Open Source Apache License. Openfire's administrative console, a web-based application, was found to be vulnerable to a path traversal attack via the setup environment. This permitted an unauthenticated user to use the unauthenticated Openfire Setup Environment in an already configured Openfire environment to access restricted pages in the Openfire Admin Console reserved for administrative users. This vulnerability affects all versions of Openfire that have been released since April 2015, starting with version 3.10.0. The problem has been patched in Openfire release 4.7.5 and 4.6.8, and further improvements will be included in the yet-to-be released first version on the 4.8 branch (which is expected to be version 4.8.0). Users are advised to upgrade. If an Openfire upgrade isn’t available for a specific release, or isn’t quickly actionable, users may see the linked github advisory (GHSA-gw42-f939-fhvm) for mitigation advice.

5.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-09-14. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-22

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openfire

Threat summary

  • Active exploitation appears in 2 classified signals
  • Exploit tooling references are present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • Technical details provided in 1 signal
  • Peaked 1d ago at 1 mentions (2026-06-25); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
openfire

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-25: 1Mentions · 2026-06-27: 1Exploit Tool / Code · 2026-06-25: 1Active Exploitation · 2026-06-25: 1Active Exploitation · 2026-06-27: 1Technical Details · 2026-06-27: 106-2506-27
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • connect24h@connect24h
    Active Exploitation

    SharkLoaderは「侵入後にCobalt Strike」までの段取りがかなり生々しい。StrikeSharkはProxyLogon、Openfire、GeoServerなど既知CVEを入口に、SystemSettings.exeのDLL side-loadingでBeaconを起こす。 Kaspersky観測ではインドネシア外交組織、台湾政府系、各国のソフトウェア開発企業まで対象。調べてみると、これはゼロデイ騒ぎより“未修正の公開系サーバが足場化する”話っぽい。CVE-2021-26855、CVE-2023-32315、CVE-2024-36401の露出、web shell、Run key、scheduled task、SystemSettings.dll、DscCoreR.mui、LSASS/NTDSアクセスのチェックを。 #セキュリティ https://thehackernews.com/2026/06/new-sharkloader-malware-deploys-cobalt.html

    Post summary

    SharkLoader is actively exploiting known CVEs to compromise organizations, using techniques like DLL side‑loading and scheduled tasks, with no patch or PoC referenced.

    00010216
    4.0K followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    The StrikeShark campaign uses SharkLoader malware to deploy Cobalt Strike Beacons by exploiting CVE-2021-26855 in Microsoft Exchange and CVE-2023-32315 in Openfire, targeting diplomatic and government sectors across Indonesia, Taiwan, and Colombia, Securelist reported. https://t.co/QXSAnBDQuB

    Post summary

    The tweet reports that the StrikeShark campaign is actively exploiting CVE-2021-26855 and CVE-2023-32315 to deploy malware targeting diplomatic and government sectors in several countries.

    10000143
    395 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appigniterealtimeopenfire---

Explore more