Malware & Threats

Apache ActiveMQ Vulnerability Exploited as Zero-Day

The recently patched Apache ActiveMQ vulnerability tracked as CVE-2023-46604 has been exploited as a zero-day since at least October 10.

The recently patched Apache ActiveMQ vulnerability tracked as CVE-2023-46604 has been exploited as a zero-day since at least October 10.

Malicious exploitation of an Apache ActiveMQ vulnerability tracked as CVE-2023-46604 started at least two weeks prior to patches being released, according to managed detection and response firm Huntress.  

Apache ActiveMQ is a popular open source, multi-protocol message broker, and there are still thousands of internet-exposed instances that are vulnerable to attacks exploiting CVE-2023-46604, which can be leveraged for remote code execution. 

A patch for the vulnerability was committed to the source code on October 24 and the existence of the security flaw was made public on October 27. 

Rapid7 started seeing exploitation attempts on the same day, with attackers apparently trying to deliver HelloKitty ransomware, whose source code was leaked in early October.

However, Huntress has found evidence that CVE-2023-46604 was exploited as a zero-day since at least October 10.

“At the time that the events were investigated, Huntress analysts found no additional, subsequent malicious activity on the endpoint, indicating that the infection process did not succeed,” the company said in a blog post on Thursday. 

Advertisement. Scroll to continue reading.

Technical details and proof-of-concept (PoC) code for CVE-2023-46604 are publicly available. In addition, exploitation of the vulnerability is trivial and there is even a Metasploit module that automates exploitation. 

That’s why it’s important that users update ActiveMQ as soon as possible to versions 5.15.16, 5.16.7, 5.17.6 or 5.18.3, which patch the flaw.

Indicators of compromise (IoCs) are available from both Rapid7 and Huntress

This is not the first Apache ActiveMQ vulnerability that has been exploited in the wild. The US cybersecurity agency CISA warned last year that CVE-2016-3088, which allows remote attackers to upload and execute arbitrary files, has also been leveraged for malicious purposes. 

Related: Companies Address Impact of Exploited Libwebp Vulnerability 

Related: Recently Patched TeamCity Vulnerability Exploited to Hack Servers

Related: Recent NetScaler Vulnerability Exploited as Zero-Day Since August

Related Content

Vulnerabilities

The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches.

Vulnerabilities

Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code.

Vulnerabilities

Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges.

Vulnerabilities

The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild.

Vulnerabilities

The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor.

Vulnerabilities

CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices.

Vulnerabilities

A use-after-free in the afd.sys Windows kernel-mode driver has been exploited to gain SYSTEM privileges.

Vulnerabilities

The security defect allows unauthenticated, remote attackers to gain administrative access to Metabase instances.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version