Technical description
Recently patched vulnerability in Apache ActiveMQ Classic is being exploited in the wild. While exploitation requires authentication, many instances use widely-known default credentials.
Attack vector
Remote authenticated users can exploit the vulnerability to execute arbitrary code. Default credentials on many installations lower the authentication barrier.
Affected systems
Unpatched Apache ActiveMQ Classic installations, particularly those with default credentials.
Mitigation
Apply Apache ActiveMQ patches immediately. Change default credentials on all ActiveMQ instances. CISA has added this to the Known Exploited Vulnerabilities catalog.