logo

Critical RCE Vulnerability

ID: 6df5733c-ed5e-5b46-84c0-78aa2c8e3218

STIX ID: report--6df5733c-ed5e-5b46-84c0-78aa2c8e3218

Feed Name: Arctic Wolf Blog

Threat Score
90/100

Date Published: 2023-11-03

Date Updated: 2026-04-27

...
...

Apache published an advisory for CVE-2023-46604, a critical unauthenticated remote code execution vulnerability in ActiveMQ (CVSS 10.0). Arctic Wolf observed active exploitation of this flaw being used to deploy the TellYouThePass ransomware, and a public proof-of-concept is available; the advisory strongly recommends upgrading ActiveMQ to fixed versions and monitoring vendor patches for bundled instances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.