Security News > 2023 > November > 3,000 Apache ActiveMQ servers vulnerable to RCE attacks exposed online

Over three thousand internet-exposed Apache ActiveMQ servers are vulnerable to a recently disclosed critical remote code execution vulnerability.
Apache ActiveMQ is a scalable open-source message broker that fosters communication between clients and servers, supporting Java and various cross-language clients and many protocols, including AMQP, MQTT, OpenWire, and STOMP. Thanks to the project's support for a diverse set of secure authentication and authorization mechanisms, it is widely used in enterprise environments where systems communicate without direct connectivity.
Researchers from threat monitoring service ShadowServer found 7,249 servers accessible with ActiveMQ services.
Of those, 3,329 were found to run an ActiveMQ version vulnerable to CVE-2023-4660, with all of these servers vulnerable to remote code execution.
Millions of Exim mail servers exposed to zero-day RCE attacks.
Thousands of Juniper devices vulnerable to unauthenticated RCE flaw.
News URL
Related news
- Critical RCE flaw in Apache Tomcat actively exploited in attacks (source)
- Online crime-as-a-service skyrockets with 24,000 users selling attack tools (source)
- Over 37,000 VMware ESXi servers vulnerable to ongoing attacks (source)
- PHP-CGI RCE Flaw Exploited in Attacks on Japan's Tech, Telecom, and E-Commerce Sectors (source)
- Critical PHP RCE vulnerability mass exploited in new attacks (source)
- Veeam RCE bug lets domain users hack backup servers, patch now (source)
- Max severity RCE flaw discovered in widely used Apache Parquet (source)
- CISA Warns of CentreStack's Hard-Coded MachineKey Vulnerability Enabling RCE Attacks (source)
- CentreStack RCE exploited as zero-day to breach file sharing servers (source)
- New BPFDoor Controller Enables Stealthy Lateral Movement in Linux Server Attacks (source)