CVE-2023-46604

Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 20, 2026 12 articles

EPSS Score

Source: FIRST.org · 2026-05-24
94.44%
probability
This CVE has a 94.44% probability of being exploited in the next 30 days.
0% Top 100.0th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Attack Intelligence

Exploits & PoC

SaumyajeetDas/CVE-2023-46604-RCE-Reverse-Shell-Apache-ActiveMQ

Achieving a Reverse Shell Exploit for Apache ActiveMQ (CVE_2023-46604)

126
evkl1d/CVE-2023-46604

PoC CVE-2023-46604 — evkl1d/CVE-2023-46604

40
duck-sec/CVE-2023-46604-ActiveMQ-RCE-pseudoshell

This script leverages CVE-2023046604 (Apache ActiveMQ) to generate a pseudo shell. The vulnerability allows for remote code execution due to unsafe de

18
justdoit-cai/CVE-2023-46604-Apache-ActiveMQ-RCE-exp

CVE-2023-46604 Apache ActiveMQ RCE exp 基于python

5
vulncheck-oss/cve-2023-46604

A go-exploit for Apache ActiveMQ CVE-2023-46604

4
5 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
92%
EPSS 94.44%
Mentions 12
Last Seen Apr 21, 2026

CNA Information

Analyst Note

CVE-2023-46604 is a critical Apache ActiveMQ RCE vulnerability (CVSS 10.0) with multiple confirmed in-the-wild exploitation reports from mid-2023, including active malware deployment (GoTitan botnet, Kinsing, HelloKitty ransomware) before patches were widely available. The 'recently disclosed' language and rapid exploitation timeline confirm zero-day status.

Threat Actors 23

MuddyWater
apt_group Information theft and espionage 🇮🇷 IR
Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
Cobalt
apt_group Financial crime 🇷🇺 RU
APT37
apt_group Information theft and espionage 🇰🇵 KP
APT 28
apt_group Information theft and espionage 🇷🇺 RU
Cron
apt_group 🇷🇺 RU
Kimsuky
apt_group Information theft and espionage 🇰🇷 KR
CHRYSENE
apt_group Information theft and espionage 🇮🇷 IR
Vicious Panda
apt_group Information theft and espionage 🇨🇳 CN
Hacking Team
apt_group 🇮🇹 IT
SCATTERED SPIDER
apt_group Financial crime 🇺🇸 US
Kinsing
apt_group 🇷🇺 RU
UAC-0020
apt_group 🇺🇦 UA
SideWinder
apt_group 🇮🇳 IN
RAZOR TIGER
apt_group Information theft and espionage 🇮🇳 IN
Larva-208
apt_group 🇷🇺 RU
GhostSec
apt_group
Storm-0530
apt_group 🇰🇵 KP
Hezb
apt_group Information theft and espionage 🇱🇧 LB
Red October
apt_group 🇷🇺 RU
Pat Bear
apt_group 🇸🇾 SY
Mana Team
apt_group 🇨🇳 CN
Sima
apt_group Information theft and espionage 🇮🇷 IR

Triage Info

Decided atMar 20, 2026