CVE-2023-46604
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 20, 2026
12 articles
EPSS Score
Source: FIRST.org · 2026-05-24
94.44%
probability
This CVE has a 94.44% probability
of being exploited in the next 30 days.
0%
Top 100.0th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Attack Intelligence
Exploits & PoC
SaumyajeetDas/CVE-2023-46604-RCE-Reverse-Shell-Apache-ActiveMQ
Achieving a Reverse Shell Exploit for Apache ActiveMQ (CVE_2023-46604)
126
evkl1d/CVE-2023-46604
PoC CVE-2023-46604 — evkl1d/CVE-2023-46604
40
duck-sec/CVE-2023-46604-ActiveMQ-RCE-pseudoshell
This script leverages CVE-2023046604 (Apache ActiveMQ) to generate a pseudo shell. The vulnerability allows for remote code execution due to unsafe de
18
justdoit-cai/CVE-2023-46604-Apache-ActiveMQ-RCE-exp
CVE-2023-46604 Apache ActiveMQ RCE exp 基于python
5
vulncheck-oss/cve-2023-46604
A go-exploit for Apache ActiveMQ CVE-2023-46604
4
5 repos — triés par ⭐
Rechercher sur GitHub ↗
CISA flags Apache ActiveMQ flaw as actively exploited in attacks
BleepingComputer
Apr 17, 2026
Actively exploited Apache ActiveMQ flaw impacts 6,400 servers
BleepingComputer
Apr 21, 2026
Oracle Critical Patch Update, January 2025 Security Update Review
Qualys
Jan 23, 2025
Oracle Patch Update, January 2024 Security Update Review
Qualys
Jan 17, 2024
Signal Intelligence
Confidence
92%
EPSS
94.44%
Mentions
12
Last Seen
Apr 21, 2026
CNA Information
Analyst Note
CVE-2023-46604 is a critical Apache ActiveMQ RCE vulnerability (CVSS 10.0) with multiple confirmed in-the-wild exploitation reports from mid-2023, including active malware deployment (GoTitan botnet, Kinsing, HelloKitty ransomware) before patches were widely available. The 'recently disclosed' language and rapid exploitation timeline confirm zero-day status.
Threat Actors 23
MuddyWater
apt_group
Information theft and espionage
🇮🇷 IR
Lazarus Group
apt_group
Information theft and espionage
🇰🇵 KP
Cobalt
apt_group
Financial crime
🇷🇺 RU
APT37
apt_group
Information theft and espionage
🇰🇵 KP
APT 28
apt_group
Information theft and espionage
🇷🇺 RU
Cron
apt_group
🇷🇺 RU
Kimsuky
apt_group
Information theft and espionage
🇰🇷 KR
CHRYSENE
apt_group
Information theft and espionage
🇮🇷 IR
Vicious Panda
apt_group
Information theft and espionage
🇨🇳 CN
Hacking Team
apt_group
🇮🇹 IT
SCATTERED SPIDER
apt_group
Financial crime
🇺🇸 US
Kinsing
apt_group
🇷🇺 RU
UAC-0020
apt_group
🇺🇦 UA
SideWinder
apt_group
🇮🇳 IN
RAZOR TIGER
apt_group
Information theft and espionage
🇮🇳 IN
Larva-208
apt_group
🇷🇺 RU
GhostSec
apt_group
Storm-0530
apt_group
🇰🇵 KP
Hezb
apt_group
Information theft and espionage
🇱🇧 LB
Red October
apt_group
🇷🇺 RU
Pat Bear
apt_group
🇸🇾 SY
Mana Team
apt_group
🇨🇳 CN
Sima
apt_group
Information theft and espionage
🇮🇷 IR
Triage Info
Decided atMar 20, 2026