logo

Apache OFBiz zero-day pummeled by exploit attempts after disclosure

ID: 21151680-7cf3-54cf-ba45-31e127a7ed08

STIX ID: report--21151680-7cf3-54cf-ba45-31e127a7ed08

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2024-01-08

Date Updated: 2026-04-26

Author: Connor Jones

...
...

SonicWall researchers disclosed active exploitation of a critical Apache OFBiz zero-day (CVE-2023-51467, CVSS 9.8) that allows authentication bypass and remote code execution. Thousands of daily exploitation attempts were observed since disclosure; users are advised to upgrade to OFBiz 18.12.11 to remediate this and an associated authentication bypass vulnerability (CVE-2023-49070).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.