Vulnerability record · CVE-2023-46604 · published 27 October 2023
CVE-2023-46604: Apache ActiveMQ OpenWire deserialization remote code execution
Apache · Activemq
The Java OpenWire protocol marshaller in Apache ActiveMQ deserializes untrusted data, letting an attacker manipulate serialized class types so the broker or client instantiates arbitrary classes on the classpath. This yields remote code execution and affects both brokers and clients, so exposure is not limited to the server side. It is a critical, actively exploited flaw with a near-certain exploitation likelihood score.
Description
The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable RCE with public exploit code, KEV listing, ransomware use and a 99.95th percentile EPSS score makes this an urgent patch-first item.
What it is
The Java OpenWire protocol marshaller in Apache ActiveMQ deserializes untrusted data, letting an attacker manipulate serialized class types so the broker or client instantiates arbitrary classes on the classpath. This yields remote code execution and affects both brokers and clients, so exposure is not limited to the server side. It is a critical, actively exploited flaw with a near-certain exploitation likelihood score.
Impact
An attacker gains arbitrary shell command execution on the target host, with full loss of confidentiality, integrity and availability. Because the flaw can be triggered on either broker or client, a compromised peer can also pivot into connecting systems.
Attack surface
Reachable over the network via the OpenWire protocol; the CVSS vector shows no privileges and no user interaction required. Any host with network access to a listening OpenWire endpoint, or able to send crafted OpenWire traffic to a client, can attempt exploitation.
Exploitation
Listed in CISA KEV with known ransomware campaign use and a due date of 2023-11-23, and EPSS 30-day probability is 0.99723 (99.95th percentile). Public exploit code is referenced (Packet Storm), so exploitation is trivial and widespread.
What to do
- Upgrade brokers and clients to ActiveMQ 5.15.16, 5.16.7, 5.17.6 or 5.18.3 as directed by the vendor advisory.
- If immediate patching is impossible, restrict network access to OpenWire ports (default 61616) to trusted hosts only and remove internet exposure.
- Apply vendor mitigations for dependent products (Debian, NetApp E-Series/SANtricity components) or discontinue use where no fix exists, per CISA KEV guidance.
- Audit for unpatched or forgotten ActiveMQ instances, including clients and embedded deployments, and confirm no unauthorized class loading paths remain.
- Monitor and block outbound connections from ActiveMQ hosts to unexpected destinations, which is common post-exploitation behavior.
Detection
- Hunt for unexpected child processes spawned by the ActiveMQ Java process (java, activemq) such as shells, curl, wget or scripting interpreters.
- Inspect OpenWire traffic and logs for malformed or unusual class type names in serialized messages, especially known gadget classes.
- Alert on outbound network connections from ActiveMQ hosts to unfamiliar IPs or ports, consistent with payload retrieval or C2.
- Review file creation and modification in ActiveMQ working directories and web roots for dropped payloads or webshells.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-46604 to the Known Exploited Vulnerabilities catalog on 2 November 2023 as "Apache ActiveMQ Deserialization of Untrusted Data Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 23 November 2023.
Affected products
6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-46604 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-46604), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.