ENISA EU KEV catalog membership for CVE-2023-46604
ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.
Vulnerability threat dossier
The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.
VTP analyst assessment
Critical untrusted-data deserialization in ActiveMQ's Java OpenWire protocol can let a network attacker execute arbitrary shell commands by manipulating serialized class types. Public known exploitation and known ransomware-campaign use are recorded; no VTP observation is established.
1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.
The bundle does not describe current campaigns, exploit tooling, or exposed-instance prevalence.
First-party activity is unknown.
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Unexpected serialized class types or anomalous OpenWire connections.
VTP deterministic assessment
CISA KEV lists this vulnerability as known to be exploited globally.
EPSS is 1.00; this is predictive context, not exploitation evidence.
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Material change ledger
Claim provenance
1 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.
Event history
CISA lists global known exploitation. This is not a VTP sensor observation.
ENISA EU KEV reports known exploitation. VTP imported this historical entry as source baseline. This is public intelligence, not a VTP sensor observation.
Original publications
ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.
Technical vulnerability data
Raw observations
First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.