The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a new critical-severity vulnerability to its KEV catalog. The issue is tracked as CVE-2023-33246 and it affects Apache's RocketMQ distributed messaging and streaming platform.
Exploiting the vulnerability is possible without authentication and has been leveraged actively by threat actors since at least June. Multiple threat actors may be actively exploiting this
Read more
Tags: streaming, and, IT, security, messaging, Apache, ADDS, threat, Infrastructure Security, New, authentication, 2023, Vulnerability, Threat Actors, CVE
Related Posts
- Warning: RocketMQ Vulnerability Actively Exploited by Threat Actorsa
- Citrix ADC zero-day exploitatation: CISA releases details about attack on CI organization (CVE-2023-3519)a
- Citrix/NetScaler vulnerability CVE-2023-3519 can cause more damage than one can imaginea
- CISA adds critical Adobe ColdFusion flaw to its Known Exploited Vulnerabilities cataloga
- CISA adds actively exploited flaw in .NET, Visual Studio to its Known Exploited Vulnerabilities cataloga