Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4996 articles · 189019 vulns · 37/41 feeds (7d)
← Back to list
10.0
CVE-2023-46604KEVEXPLOITEDPATCHED
apache · activemq

The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to r

Description

The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.

Affected Products

VendorProductVersions
apacheactivemq< 5.15.16, < 5.16.7, < 5.17.6, < 5.18.3, < 5.15.16, < 5.16.7, < 5.17.6, < 5.18.3, < 5.19.4, 6.0.0 - 6.2.3, 6.2.3

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
apacheactivemq_legacy_openwire_modulecve_cpe95%
atlassianfisheyecert_advisory90%
atlassianconfluencecert_advisory90%
atlassianbitbucketcert_advisory90%
atlassiancruciblecert_advisory90%

References

  • http://seclists.org/fulldisclosure/2024/Apr/18(Mailing List, Third Party Advisory)
  • https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt(Vendor Advisory)
  • https://lists.debian.org/debian-lts-announce/2023/11/msg00013.html(Mailing List)
  • https://packetstormsecurity.com/files/175676/Apache-ActiveMQ-Unauthenticated-Remote-Code-Execution.html(Exploit, Third Party Advisory, VDB Entry)
  • https://security.netapp.com/advisory/ntap-20231110-0010/(Third Party Advisory)
  • https://www.openwall.com/lists/oss-security/2023/10/27/5(Mailing List)
  • http://seclists.org/fulldisclosure/2024/Apr/18(Mailing List, Third Party Advisory)
  • https://activemq.apache.org/security-advisories.data/CVE-2023-46604-announcement.txt(Vendor Advisory)
  • https://lists.debian.org/debian-lts-announce/2023/11/msg00013.html(Mailing List)
  • https://lists.debian.org/debian-lts-announce/2024/10/msg00027.html(Mailing List)
  • https://packetstormsecurity.com/files/175676/Apache-ActiveMQ-Unauthenticated-Remote-Code-Execution.html(Exploit, Third Party Advisory, VDB Entry)
  • https://security.netapp.com/advisory/ntap-20231110-0010/(Third Party Advisory)
  • https://www.openwall.com/lists/oss-security/2023/10/27/5(Mailing List)
  • https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-46604(Third Party Advisory, US Government Resource)

Related News (5 articles)

Tier B
BSI Advisories12h ago
[UPDATE] [hoch] Oracle Communications: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
BSI Advisories84d ago
[NEU] [hoch] Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye und Jira): Mehrere Schwachstellen
→ No new info (linked only)
Tier D
BleepingComputer113d ago
Actively exploited Apache ActiveMQ flaw impacts 6,400 servers
→ No new info (linked only)
Tier D
BleepingComputer117d ago
CISA flags Apache ActiveMQ flaw as actively exploited in attacks
→ No new info (linked only)
Tier D
BleepingComputer126d ago
13-year-old bug in ActiveMQ lets hackers remotely execute commands
→ No new info (linked only)
CVSS 3.110.0 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
5.15.165.16.75.17.65.18.3
CWECWE-502, CWE-284, CWE-20
PublishedOct 27, 2023
Last enriched113d agov4
Tags
RCEActiveMQCVE-2026-34197CVE-2026-35616CVE-2023-46604CVE-2016-3088
Trending Score107🔥
Source articles5
Independent2
Info Completeness11/14
Missing: epss, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-49975EXP
Apache HTTP Server: mod_http2 denial of service
Trending: 86
MEDIUMCVE-2026-57914EXP
Apache Kerby: StackOverflow on parsing deeply nested ASN1 structures
Trending: 56
HIGHCVE-2026-57915
Apache Kerby: Kerberos Pre-Authentication Bypass
Trending: 51
CRITICALCVE-2026-34191
Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle
Trending: 43
HIGHCVE-2026-55969
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()
Trending: 42

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Oct 27, 2023
Added to CISA KEV
Oct 27, 2023
Actively Exploited
Nov 4, 2025
Exploit Available
Nov 4, 2025
Patch Available
Nov 4, 2025
Discovered by ZDM
Apr 1, 2026
Updated: affectedVersions, cweIds, tags
Apr 8, 2026
Updated: cweIds, tags
Apr 17, 2026
Updated: affectedVersions
Apr 21, 2026

Version History

v4
Last enriched 113d ago
v4Tier D113d ago

Updated affected versions to include 6.2.3 and 5.19.4, changed severity to HIGH, and added new IoCs and tags.

affectedVersions
via BleepingComputer
v3Tier D117d ago

Updated severity to HIGH, added new patch versions 6.2.3 and 5.19.4, included new CWE ID CWE-20, and added new relevant CVE tags.

cweIdstags
via BleepingComputer
v2Tier D126d ago

Updated description with detailed exploit information, changed severity to HIGH, updated CVSS to 8.8, and added new affected versions and CVE IDs.

affectedVersionscweIdstags
via BleepingComputer
v1133d ago

Initial creation