What happened
Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire protocol to cause the broker to instantiate any class on the classpath.
Affected versions
ActiveMQ: See original advisory Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
PoC-in-GitHub · trganda/ActiveMQ-RCECVE-2023-46604★ 28trganda2023-10-26CandidatePoC-in-GitHub · SaumyajeetDas/CVE-2023-46604-RCE-Reverse-Shell-Apache-ActiveMQAchieving a Reverse Shell Exploit for Apache ActiveMQ (CVE_2023-46604)★ 126SaumyajeetDas2023-11-03CandidatePoC-in-GitHub · evkl1d/CVE-2023-46604★ 41evkl1d2023-11-04CandidatePoC-in-GitHub · justdoit-cai/CVE-2023-46604-Apache-ActiveMQ-RCE-expCVE-2023-46604 Apache ActiveMQ RCE exp 基于python★ 5justdoit-cai2023-11-08CandidatePoC-in-GitHub · h3x3h0g/ActiveMQ-RCE-CVE-2023-46604-Write-up★ 3h3x3h0g2023-11-09CandidatePoC-in-GitHub · duck-sec/CVE-2023-46604-ActiveMQ-RCE-pseudoshellThis script leverages CVE-2023046604 (Apache ActiveMQ) to generate a pseudo shell. The vulnerability allows for remote code execution due to unsafe deserialization within the OpenWire protocol.★ 19duck-sec2023-11-12CandidatePoC-in-GitHub · vjayant93/CVE-2023-46604-POCPOC repo for CVE-2023-46604★ 0vjayant932023-11-15CandidatePoC-in-GitHub · LiritoShawshark/CVE-2023-46604_ActiveMQ_RCE_RecurrenceCVE-2023-46604环境复现包★ 2LiritoShawshark2023-11-16CandidatePoC-in-GitHub · NKeshawarz/CVE-2023-46604-RCE★ 4NKeshawarz2023-11-18CandidatePoC-in-GitHub · minhangxiaohui/ActiveMQ_CVE-2023-46604PY★ 1minhangxiaohui2023-11-20CandidatePoC-in-GitHub · CrackerCat/ActiveMQ_RCE_Pro_MaxCVE-2023-46604★ 0CrackerCat2023-11-20CandidatePoC-in-GitHub · nitzanoligo/CVE-2023-46604-demo★ 0nitzanoligo2023-11-20CandidatePoC-in-GitHub · dcm2406/CVE-LabInstructions for exploiting vulnerabilities CVE-2021-44228 and CVE-2023-46604★ 2dcm24062023-12-07CandidatePoC-in-GitHub · mrpentst/CVE-2023-46604Exploit for CVE-2023-46604★ 2mrpentst2023-12-09CandidatePoC-in-GitHub · dcm2406/CVE-2023-46604★ 0dcm24062023-12-16CandidatePoC-in-GitHub · Mudoleto/Broker_ApacheMQCVE-2023-46604 - ApacheMQ Version 5.15.5 Vulnerability Machine: Broker★ 0Mudoleto2023-12-23CandidatePoC-in-GitHub · tomasmussi/activemq-cve-2023-46604Repository to exploit CVE-2023-46604 reported for ActiveMQ★ 0tomasmussi2023-12-30CandidatePoC-in-GitHub · stegano5/ExploitScript-CVE-2023-46604★ 1stegano52024-02-14CandidatePoC-in-GitHub · Arlenhiack/ActiveMQ-RCE-ExploitActiveMQ RCE (CVE-2023-46604) 回显利用工具★ 45Arlenhiack2024-03-05CandidatePoC-in-GitHub · vulncheck-oss/cve-2023-46604A go-exploit for Apache ActiveMQ CVE-2023-46604★ 4vulncheck-oss2024-04-17CandidatePoC-in-GitHub · thinkycx/activemq-rce-cve-2023-46604activemq-rce-cve-2023-46604★ 0thinkycx2024-04-26CandidatePoC-in-GitHub · mranv/honeypot.rsCVE-2023-46604 (Apache ActiveMQ RCE Vulnerability) and focused on getting Indicators of Compromise.★ 0mranv2024-05-29CandidatePoC-in-GitHub · pulentoski/CVE-2023-46604El script explota una vulnerabilidad de deserialización insegura en Apache ActiveMQ (CVE-2023-46604)★ 1pulentoski2024-05-31CandidatePoC-in-GitHub · cuanh2333/CVE-2023-46604★ 0cuanh23332024-10-16CandidatePoC-in-GitHub · skrkcb2/CVE-2023-46604★ 1skrkcb22025-02-27CandidatePoC-in-GitHub · CCIEVoice2009/CVE-2023-46604★ 0CCIEVoice20092025-05-04CandidatePoC-in-GitHub · vaishnavucv/Project-Vuln-Detection-N-Mitigation_101Vulnerability Detection and Mitigation Apache ActiveMQ | Security Architectures and Systems Administration - on - Apache ActiveMQ Deserialization Remote Code Execution (RCE) – CVE-2023-46604★ 1vaishnavucv2025-09-08CandidatePoC-in-GitHub · pavanaa4k/CVE-2023-46604-LABDetection, Exploit and Mitigation for CVE 2023 46604.★ 0pavanaa4k2025-11-15CandidatePoC-in-GitHub · RockyDesigne/SSP-Assignment-3-RCEYouLaterA PoC for CVE-2023-46604 written as part of SPS class for the Advanced Cyber Security master's at UPB.★ 2RockyDesigne2026-01-04CandidatePoC-in-GitHub · sangrok-jeon/CVE-2023-46604-AnalysisApache ActiveMQ OpenWire 역직렬화 RCE 취약점 기술 분석★ 0sangrok-jeon2026-03-15CandidatePoC-in-GitHub · mkdemir/activemq-lockbit-analysisApache ActiveMQ (CVE-2023-46604) zafiyetinden LockBit ransomware aşamasına uzanan 419 saatlik sızma vakasının uçtan uca analizi, SIEM korelasyon kuralları ve IOC listesi.★ 0mkdemir2026-03-30CandidatePoC-in-GitHub · Catherines77/ActiveMQ-EXPtoolsApache ActiveMQ漏洞综合利用工具(CVE-2015-5254,CVE-2016-3088,CVE-2022-41678,CVE-2023-46604,CVE-2024-32114,CVE-2026-34197,CVE-2026-40466, CVE-2026-42588)★ 83Catherines772026-04-20CandidatePoC-in-GitHub · Navya240/intel471-threat-hunting-cve-2023-46604My first hands-on Intel 471 threat hunting workshop experience investigating CVE-2023-46604 using Elastic SIEM, vulnerability intelligence, and post-exploitation detection.★ 0Navya2402026-04-30CandidatePoC-in-GitHub · KlaasStessens/CVE-2023-46604Exploitation of CVE-2023-44604. Using a Kali Linux VM (attacker) and a Debian 11 server VM (victim)★ 0KlaasStessens2026-05-01CandidatePoC-in-GitHub · trnguyen03/activemq-ids-ips-labIDS/IPS lab for detecting and preventing Apache ActiveMQ RCE (CVE-2023-46604) using GVM, Nmap, Snort, iptables, and UFW.★ 0trnguyen032026-05-02CandidatePoC-in-GitHub · REGGYRAIDER/CVE-2023-46604-RCECVE-2023-46604-RCE exploit with Linux reverse shell payload★ 0REGGYRAIDER2026-06-06CandidatePoC-in-GitHub · aelshimony-cloud/OpenWire-CVE-2023-46604-Investigation★ 0aelshimony-cloud2026-06-20CandidatePoC-in-GitHub · stefanotractor/activemq-cve-2023-46604-lab★ 0stefanotractor2026-08-19CandidatePoC-in-GitHub · Bhanunamikaze/ActiveMQ-CVE-2023-46604Exploit POC for Apache ActiveMQ CVE-2023-46604★ 0Bhanunamikaze2026-09-01CandidateSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.