All CVEs
Vulnerability intelligence

CVE-2023-46604

Apache ActiveMQ Deserialization of Untrusted Data Vulnerability

Apache ActiveMQ CWE-502

The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.

CVSS Score
10
Critical
EPSS — Exploit Probability
100%
Riskier than 100% of all CVEs · checked 2026-09-08
Exploitation
Confirmed in the wild
Used in ransomware campaigns
Remediation
Unconfirmed
Federal deadline 2023-11-23
CISA required action

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Deadline for federal agencies: 2023-11-23.

NVD entry CISA KEV

1 article across 1 outlet · first covered Feb 26, 2026 · latest Feb 26, 2026

Coverage timeline

Related CVEs — Apache