logo

CVE-2023-33246

ID: e99e9831-f467-5cf8-be8a-5c5b8f38feef

STIX ID: report--e99e9831-f467-5cf8-be8a-5c5b8f38feef

Feed Name: Arctic Wolf Blog

Threat Score
80/100

Date Published: 2023-08-28

Date Updated: 2026-04-27

...
...

On May 23, 2023 Apache patched CVE-2023-33246, a critical remote code execution vulnerability in RocketMQ components exposed to the Internet; multiple threat actors have actively exploited this flaw since at least June 2023 to gain initial access and deploy the DreamBus Linux botnet. Arctic Wolf strongly recommends upgrading to RocketMQ 4.9.6/5.1.1 or above and following organizational patching/testing procedures. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.