CVE-2023-46604Active Exploitation(apache / activemq)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 7 mentions and remains active

Immediate actions

  • Patch apache activemq systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.

9.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-11-23. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-502

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • activemq
  • activemq_legacy_openwire_module
  • debian_linux
  • e-series_santricity_unified_manager

Threat summary

  • Active exploitation appears in 19 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 39 mentions across 23 observed days

What's happening

  • Active exploitation reported across 19 signals
  • Exploit tool or code specified in 9 signals
  • PoC mentioned or linked in 7 signals
  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 18 signals
  • Disclosure: 9 classified signals
  • Peaked 21d ago at 7 mentions (2026-02-25); latest day: 1
  • 39 total mentions across 23 days

Affected systems

Products
activemqactivemq_legacy_openwire_moduledebian_linuxe-series_santricity_unified_managere-series_santricity_web_services_proxysantricity_storage_plugin

3 versions affected across 6 products

Deep dive

Activity timeline39 mentions / 23d
02457Mentions · 2026-02-24: 2Mentions · 2026-02-25: 7Mentions · 2026-02-26: 1Mentions · 2026-02-27: 2Mentions · 2026-03-03: 1Mentions · 2026-03-04: 1Mentions · 2026-03-05: 1Mentions · 2026-03-28: 1Mentions · 2026-04-07: 1Mentions · 2026-04-17: 1Mentions · 2026-04-22: 2Mentions · 2026-04-29: 5Mentions · 2026-05-23: 1Mentions · 2026-06-08: 1Mentions · 2026-08-20: 2Mentions · 2026-08-24: 2Mentions · 2026-09-03: 2Mentions · 2026-09-14: 1Mentions · 2026-09-27: 1Mentions · 2026-09-28: 1Mentions · 2026-10-02: 1Mentions · 2026-10-05: 1Mentions · 2026-10-06: 1PoC Mentioned / Linked · 2026-02-25: 1PoC Mentioned / Linked · 2026-04-07: 1PoC Mentioned / Linked · 2026-06-08: 1PoC Mentioned / Linked · 2026-08-20: 1PoC Mentioned / Linked · 2026-08-24: 1PoC Mentioned / Linked · 2026-09-03: 1PoC Mentioned / Linked · 2026-09-14: 1Exploit Tool / Code · 2026-02-24: 2Exploit Tool / Code · 2026-02-27: 2Exploit Tool / Code · 2026-03-04: 1Exploit Tool / Code · 2026-06-08: 1Exploit Tool / Code · 2026-08-20: 1Exploit Tool / Code · 2026-08-24: 1Exploit Tool / Code · 2026-09-03: 1Active Exploitation · 2026-02-24: 2Active Exploitation · 2026-02-25: 6Active Exploitation · 2026-02-26: 1Active Exploitation · 2026-02-27: 2Active Exploitation · 2026-03-04: 1Active Exploitation · 2026-03-05: 1Active Exploitation · 2026-04-07: 1Active Exploitation · 2026-04-17: 1Active Exploitation · 2026-04-22: 2Active Exploitation · 2026-04-29: 2Patch / Workaround · 2026-02-25: 3Patch / Workaround · 2026-02-26: 1Patch / Workaround · 2026-04-07: 1Patch / Workaround · 2026-04-17: 1Patch / Workaround · 2026-04-29: 1Technical Details · 2026-02-24: 1Technical Details · 2026-02-25: 4Technical Details · 2026-03-04: 1Technical Details · 2026-04-07: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-22: 2Technical Details · 2026-04-29: 4Technical Details · 2026-05-23: 1Technical Details · 2026-08-20: 1Technical Details · 2026-08-24: 1Technical Details · 2026-09-14: 102-2402-2603-0303-0504-0704-2205-2308-2009-0309-2710-0210-06
Signal classification5 categories
Active Exploitation
1852.9%
Disclosure
926.5%
Exploit
411.8%
PoC
25.9%
General
12.9%
Referenced assets31 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-242
Active Exploitation2
2026-02-257
Active Exploitation6PoC1
2026-02-261
Active Exploitation1
2026-02-272
Active Exploitation2
2026-03-031
General1
2026-03-041
Active Exploitation1
2026-03-051
Active Exploitation1
2026-03-281
Disclosure1
2026-04-071
Disclosure1
2026-04-171
Active Exploitation1
2026-04-222
Active Exploitation2
2026-04-295
Active Exploitation2Disclosure3
2026-05-231
Disclosure1
2026-06-081
Exploit1
2026-08-202
Disclosure1Exploit1
2026-08-242
Disclosure1Exploit1
2026-09-032
Disclosure1Exploit1
2026-09-141
PoC1
Full discourse20 posts
  • Clandestine@akaclandestine
    Exploit

    GitHub - Catherines77/ActiveMQ-EXPtools: Apache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588) · GitHub https://github.com/Catherines77/ActiveMQ-EXPtools

    Post summary

    A GitHub repository offers exploitation tools for multiple ActiveMQ CVEs, indicating available code for exploitation but no evidence of active attacks, patches, or debunking.

    013051324.4K
    62.7K followersView on X
  • 📕「マルウエアの教科書」著者 | 吉川孝志 | 増補改訂版🌟発売中@MalwareBibleJP
    Active Exploitation

    Apache ActiveMQの既知の脆弱性(CVE-2023-46604)を突かれ、最終的にLockBitランサムウェアの展開に至った侵害事例が報告されています。 特徴的なのは、攻撃者が一度排除された後、18日後にまったく同じ手口で再侵入し、今度は90分足らずでランサムウェアを実行した点です。 ここまで素早く進められた理由は、初回の侵入時にWindowsの認証情報を盗み出しており、それがリセットされないまま残っていたため。 侵入経路を塞ぐだけでなく、盗まれた可能性のある認証情報も併せて無効化しなければ、攻撃者は簡単に戻ってこられるという教訓が得られる事例です。 【攻撃の流れと詳細のまとめ】 ・Apache ActiveMQは、システム間でメッセージをやり取りするために広く使われるミドルウェア。今回悪用されたCVE-2023-46604は、このActiveMQに細工したデータを送ることで、サーバー上で任意のコードを実行できてしまうRCE(リモートコード実行)の脆弱性 ・2024年2月、インターネットに公開されていたActiveMQサーバーがこの脆弱性で侵害された。攻撃者はまず、遠隔操作用のツール(Metasploit)をサーバーに送り込んで実行させ、遠隔から自由に操作できる状態を確立 ・侵入から約40分後、Windowsの最高権限であるSYSTEM権限を奪取。続いてLSASS(Windowsがログイン中のユーザーの認証情報をメモリ上に保持するプロセス)にアクセスし、ドメイン管理者を含む資格情報を窃取 ・盗んだ管理者アカウントを使い、ネットワーク内の他のサーバーへ次々と侵入を拡大。ただし一部のホストではWindows Defenderがこの動きを検知・阻止 ・2日目に攻撃者はアクセスを失ったが、ActiveMQサーバーはパッチ未適用のまま放置されていた ・18日後、攻撃者は同じ脆弱性を使って同じサーバーに再侵入。同じ遠隔操作サーバーに接続し、初回で盗んでいた特権アカウントの資格情報を使い、わずか20分で他のサーバーへの横展開を開始 ・再侵入後、遠隔操作用にAnyDeskをインストールして足場を固め、バッチファイルでRDP(リモートデスクトップ)の通信を許可するようファイアウォール設定を変更。さらにイベントログの消去や、Windows標準の実行ファイルを悪用したDefenderの無効化といった痕跡消しも実施 ・その後、RDPでバックアップサーバーやファイルサーバーに接続し、LockBitランサムウェアを配置・実行。約4時間かけてネットワーク全体に展開し、ファイルを暗号化 ・使用されたランサムウェアはLockBit Blackの特徴と一致するが、身代金要求文は通常のLockBitとは異なり、Torリークサイトへの誘導ではなくSessionという匿名メッセンジャーでの連絡を指示する内容。流出したLockBitのビルダーツールを使って独自に作成されたものと評価されている https://thedfirreport.com/2026/02/23/apache-activemq-exploit-leads-to-lockbit-ransomware/

    Post summary

    The report details a real‑world exploitation of CVE‑2023‑46604 in Apache ActiveMQ, leading to credential theft, lateral movement, and LockBit ransomware deployment, highlighting the active use of the vulnerability in the wild.

    07043152.7K
    5.0K followersView on X
  • Yusuf Can Çakır@Yusufcancakiir
    Exploit

    Not much on the menu today 😄 Found an exposed directory on 150.40.117[.]90:8000 with: Tomcat Tribes / CVE-2026-34486 tooling ActiveMQ CVE-2023-46604 exploit code Docker API scripts targeting port 2375 JWT signature testing against tokens pulled from Elasticsearch A few hardcoded targets and reverse-shell callbacks The Tomcat payload simply runs id and writes the result into the webroot, while the ActiveMQ setup calls back to 150.40.117[.]90:8080. Nothing too fancy today, just someone's exploit drawer left open 😅 If you've come across something interesting today, I'd like to see it too. IOC: 150.40.117[.]90:8000

    Post summary

    The author revealed an exposed server containing multiple exploitable CVEs, including Tomcat and ActiveMQ, with functional exploit code shared and no mention of patches or active attacks.

    25025121.7K
    1.7K followersView on X
  • Virus Bulletin@virusbtn
    Active Exploitation

    The DFIR Report documents the exploitation of an unpatched ActiveMQ server by CVE-2023-46604. The threat actor used Metasploit tooling for privilege escalation, LSASS access and lateral movement, before LockBit was deployed via RDP using stolen credentials https://thedfirreport.com/2026/02/23/apache-activemq-exploit-leads-to-lockbit-ransomware/ https://t.co/YJXu6460Yu

    Post summary

    The post reports a real‑world exploitation of CVE‑2023‑46604 on an unpatched ActiveMQ server, with attackers leveraging Metasploit for privilege escalation and deploying LockBit ransomware via RDP.

    2702531.5K
    60.8K followersView on X
  • SOCRadar®@socradar
    Active Exploitation

    North Korean state-backed group Andariel is actively exploiting critical vulnerabilities like CVE-2023-46604 and CVE-2023-42793. Leveraging tools like Ladon and AnyDesk, they are backdooring networks. Read more at the link below. https://socradar.io/blog/dark-web-profile-andariel/ #CyberSecurity #Andariel #ThreatIntel

    Post summary

    The post reports that the North Korean group Andariel is actively exploiting CVE-2023-46604 and CVE-2023-42793 using tools such as Ladon and AnyDesk.

    0601610804
    5.6K followersView on X
  • rootsecdev@rootsecdev
    PoC

    I modified an exploit POC three years ago and played around with this. https://github.com/rootsecdev/CVE-2023-46604

    Post summary

    The user references a modified exploit PoC for CVE-2023-46604 and provides a GitHub link, but no further technical details or exploitation claims are given.

    0201032.3K
    26.2K followersView on X
  • ٱلطَّيِّبُ | Mustafa El Tayeb@T4T4R1S

    Rooted Broker on #HackTheBox: ActiveMQ RCE (CVE-2023-46604) -> sudo/nginx misconfig -> root. Full writeup: [https://t4t4r1s.github.io/posts/Broker/] #CTF #InfoSec https://t.co/hOt3CVLPWv

    000101356
    338 followersView on X
  • Gray Hats@the_yellow_fall
    Active Exploitation

    The DFIR Report reveals how a persistent attacker exploited CVE-2023-46604 twice in 18 days to deploy LockBit ransomware. Patch your ActiveMQ servers now! #ActiveMQ #CyberSecurity #LockBit #Ransomware #InfoSec #PatchAlert #TheDFIRReport #RCE https://securityonline.info/unpatched-activemq-flaw-leads-to-repeat-breach-and-lockbit-ransomware/

    Post summary

    CVE‑2023‑46604 was actively exploited twice in 18 days to deploy LockBit ransomware, prompting an urgent patch for ActiveMQ servers.

    03062439
    10.4K followersView on X
  • ExploitGrid@exploitgrid
    Disclosure

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: CVE-2023-22527 CVE-2023-22518 CVE-2023-46604 CVE-2024-25600 CVE-2023-41892 ..🧵👇

    Post summary

    The post lists several newly disclosed CVEs without providing further technical details, exploits, or mitigation information.

    1102042
    38 followersView on X
  • ExploitGrid@exploitgrid
    Disclosure

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: #CVE-2023-46604 CVE-2026-61241 CVE-2025-6934 CVE-2025-24893 CVE-2026-60137 CVE-2026-63030 ..🧵👇

    Post summary

    The tweet lists several newly disclosed CVEs, but provides no technical details, exploits, or mitigation information.

    1001091
    37 followersView on X
  • CybersecInsider@Cybersecinsider
    Disclosure

    The Threat That Can’t Be Ignored: CVE-2023-46604 in Apache ActiveMQ https://ow.ly/KyVx50YA1aJ #CyberSecurity #Technology

    Post summary

    The text announces CVE-2023-46604 affecting Apache ActiveMQ but offers no substantive details or supporting technical information.

    01010145
    11.2K followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    [EXPLOIT] EGE-GH-Ej4vfGR [CRITICAL/PoC] Linked: CVE-2023-46604 ActiveMQ-CVE-2023-46604 🔗 https://exploitgrid.net/exploits/b4e2387c-3196-460a-a7ce-bca8e1a6c696

    Post summary

    The post advertises a critical PoC exploit for CVE-2023-46604 with an available code link, but it does not mention active use in the wild nor any mitigation steps.

    1000031
    40 followersView on X
  • ExploitGrid@exploitgrid
    Disclosure

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: CVE-2021-44228 CVE-2023-46604 CVE-2024-39700 CVE-2025-39401 CVE-2026-0768 ..🧵👇

    Post summary

    The tweet announces five critical CVEs that were disclosed today, but it provides no additional details.

    1000041
    40 followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    [EXPLOIT] EGE-CX-izsEE3h [CRITICAL/PoC] Linked: CVE-2023-46604 ActiveMQ-5.18.2 RCE-shell-reverse-Metasploit 🔗 https://exploitgrid.net/exploits/ab363881-a162-4718-aa0f-74fc71d4670a

    Post summary

    A proof‑of‑concept RCE for ActiveMQ 5.18.2 is available via a Metasploit module, but there is no evidence of wild exploitation or patch availability.

    1000034
    38 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    HelloKitty Ransomware (October 2023)[^2] Initial access via CVE-2023-46604 Deployment of Chisel tunneling tool for lateral movement Exfiltration via Rclone Encryption with HelloKitty ransomware

    Post summary

    HelloKitty ransomware used CVE-2023-46604 for initial access, deploying Chisel for lateral movement and Rclone for exfiltration, but no PoC, patch, or detailed vulnerability information is disclosed.

    1000071
    125 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2023-46604: CVE-2023-46604: Apache ActiveMQ OpenWire Deserialization RCE... (< 5.18.3 → 10.0)

    Post summary

    The text announces CVE-2023-46604, an Apache ActiveMQ OpenWire deserialization RCE affecting versions below 5.18.3 or 10.0, but provides no PoC, exploitation code, or patch details.

    1000059
    125 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    References: Apache Security Advisory: CVE-2023-46604 - ActiveMQ RCE Vulnerability: Rapid7 Analysis: ActiveMQ CVE-2023-46604 in HelloKitty Ransomware Campaigns: Apache ActiveMQ Release: Version 5.18.3 Security Patch

    Post summary

    CVE‑2023‑46604 is an ActiveMQ RCE flaw that has been exploited in HelloKitty ransomware attacks and is mitigated by the 5.18.3 patch.

    1000092
    125 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2023-46604 is a maximum-severity remote code execution vulnerability in Apache ActiveMQ's OpenWire protocol. By exploiting unsafe deserialization of ClassPathXmlApplicationContext objects, unauthenticated attackers can achieve arbitrary code execution on ActiveMQ…

    Post summary

    The text announces a maximum‑severity remote code execution flaw in Apache ActiveMQ caused by unsafe deserialization, but it does not provide a PoC, exploit, or mitigation details.

    1000056
    125 followersView on X
  • ThreadLinqs@threadlinqs
    Active Exploitation

    NEW THREAT INTEL: Apache ActiveMQ CVE-2023-46604 - CVSS 10.0 unauth RCE exploited by HelloKitty, Kinsing, Andariel (Lazarus) against 6,400+ brokers. 9 detections, 32 IOCs. https://intel.threadlinqs.com/#TL-2026-0404 #ThreatIntel #CyberSecurity #CVE #ActiveMQ #Lazarus

    Post summary

    The text reports widespread active exploitation of CVE-2023-46604 against Apache ActiveMQ brokers by known threat actors, highlighting a critical unauthenticated RCE.

    00001166
    24 followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** Apache ActiveMQ — Consolidated RCE and Jolokia/OpenWire/Fileserver issues (CVE-2026-34197 + CVE-2024-32114 + CVE-2022-41678 + CVE-2023-46604 + CVE-2016-3088) 📅 **Timeline:** Disclosure: 2026-04-07, Patch: unknown 🆔 **CVE-2026-34197** | 📊 CVSS: 8.8 (HIGH 🟠) | 📈 EPSS: 18.84% 🆔 **CVE-2024-32114** | 📊 CVSS: 8.8 (HIGH 🟠) | 📈 EPSS: 83.74% 🆔 **CVE-2022-41678** | 📊 CVSS: 8.8 (HIGH 🟠) | 📈 EPSS: 99.84% 🆔 **CVE-2023-46604** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 99.99% 🆔 **CVE-2016-3088** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 99.94% 🛠️ **Exploit Maturity:** Proof-of-Concept (CVE-2026-34197); others vary (public exploits and known-exploited indications) 📂 **Affected Versions:** ActiveMQ Classic before 6.2.3 / before 5.19.4, ActiveMQ 6.0.0–6.1.1, Brokers/clients prior to 5.15.16/5.16.7/5.17.6/5.18.3, ActiveMQ 5.x before 5.14.0 🔧 **Fixed Versions:** 6.2.3, 5.19.5, 6.1.2, 5.16.6/5.17.4/5.18.0, 5.15.16/5.16.7/5.17.6/5.18.3 🫨 **Attack Vectors:** - Jolokia HTTP-to-JMX addNetworkConnector with vm://brokerConfig=xbean -> remote Spring XML load -> bean instantiation -> RCE - Unauthenticated Jolokia API (/api) in default ActiveMQ 6.0.0–6.1.1 - Jolokia ExecHandler / reflection-based exec via MBeans after authentication - OpenWire Java marshaller deserialization/manipulation leading to class instantiation and RCE - Fileserver webapp HTTP PUT + MOVE to upload and execute files 📝 **Summary:** Multiple ActiveMQ flaws allow remote code execution via Jolokia (remote JMX calls and exec handlers), OpenWire marshaller deserialization, and legacy fileserver upload/MOVE abuse; some are exploitable remotely without authentication in default configs. Successful exploitation can run commands as the ActiveMQ process, manipulate messages, and lead to full host compromise or outbound fetches to attacker-controlled hosts. 📈 **Impact Scope:** Remote code execution as the broker process, potential full host compromise, unauthorized produce/consume/purge of messages, and observable outbound HTTP fetches; high real-world exploitability indicated by elevated EPSS for several CVEs. 🛡️ **Recommended Actions:** - Apply vendor fixes immediately (see fixed versions above). - If you cannot patch now: block access to API/web endpoints, restrict Jolokia, and require Jetty authentication. - Rotate and audit broker credentials (remove default admin:admin) and block/monitor outbound HTTP from broker hosts. - Hunt logs for vm:// brokerConfig=xbean indicators, unexpected child processes, and run host EDR/forensics on suspected systems. 🪢 **Related Resources:** - https://horizon3.ai/intelligence/blogs/cve-2026-34197-activemq-rce-jolokia/ - https://activemq.apache.org/security-advisories.data/CVE-2026-34197-announcement.txt 🏷 **Tags:** #Cybersecurity #ApacheActiveMQ #RCE

    Post summary

    The post announces multiple CVEs in Apache ActiveMQ with detailed vulnerability and exploitation information, confirms active exploitation in the wild, and urges immediate patching or mitigations.

    0001062
    276 followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Appapacheactivemq---
Appapacheactivemq_legacy_openwire_module---
OSdebiandebian_linux10.0--
OSdebiandebian_linux11.0--
Appnetappe-series_santricity_unified_manager---
Appnetappe-series_santricity_web_services_proxy---
Appnetappsantricity_storage_plugin-vcenter-

Explore more