Vendor

Apache Software Foundation

Apache Software Foundation news

Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

Armatura LLC Armatura One

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-control system. The following versions of Armatura LLC Armatura One are affected: Armatura One <4.7.2 (CVE-2023-46604, CVE-2026-94591, CVE-2026-94592, CVE-2026-94593…

Why it matters

CISA lists this as exploited in the wild and known to be used in ransomware campaigns. Unpatched ActiveMQ systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Recent intelligence

The latest developments from the last 30 days, newest first.

  1. AdvisoryKEV

    Armatura LLC Armatura One

    Basis: CISA Cybersecurity Advisories (government advisory)

Actively exploited

All 40 →

Apache Tomcat

Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Added Aug 4, 2026Fed. due Aug 7, 2026

Apache ActiveMQ

Apache ActiveMQ Improper Input Validation Vulnerability

Added Apr 16, 2026Fed. due Apr 30, 2026

Apache HTTP Server

Apache HTTP Server Improper Escaping of Output Vulnerability

Added May 1, 2025Fed. due May 22, 2025

Apache Tomcat

Apache Tomcat Path Equivalence Vulnerability

Added Apr 1, 2025Fed. due Apr 22, 2025

Apache OFBiz

Apache OFBiz Forced Browsing Vulnerability

Added Feb 4, 2025Fed. due Feb 25, 2025

Apache HugeGraph-Server

Apache HugeGraph-Server Improper Access Control Vulnerability

Added Sep 18, 2024Fed. due Oct 9, 2024

Apache OFBiz

Apache OFBiz Incorrect Authorization Vulnerability

Added Aug 27, 2024Fed. due Sep 17, 2024

Apache OFBiz

Apache OFBiz Path Traversal Vulnerability

Added Aug 7, 2024Fed. due Aug 28, 2024

Apache Flink

Apache Flink Improper Access Control Vulnerability

Added May 23, 2024Fed. due Jun 13, 2024

Apache Superset

Apache Superset Insecure Default Initialization of Resource Vulnerability

Added Jan 8, 2024Fed. due Jan 29, 2024
CVE-2023-46604RansomwareCVSS 9.8

Apache ActiveMQ

Apache ActiveMQ Deserialization of Untrusted Data Vulnerability

Added Nov 2, 2023Fed. due Nov 23, 2023Coverage →

Apache RocketMQ

Apache RocketMQ Command Execution Vulnerability

Added Sep 6, 2023Fed. due Sep 27, 2023

Apache Tomcat

Apache Tomcat Remote Code Execution Vulnerability

Added May 12, 2023Fed. due Jun 2, 2023
CVE-2021-45046RansomwareCVSS 9.0

Apache Log4j2

Apache Log4j2 Deserialization of Untrusted Data Vulnerability

Added May 1, 2023Fed. due May 22, 2023

Apache Spark

Apache Spark Command Injection Vulnerability

Added Mar 7, 2023Fed. due Mar 28, 2023

Apache APISIX

Apache APISIX Authentication Bypass Vulnerability

Added Aug 25, 2022Fed. due Sep 15, 2022

Apache CouchDB

Apache CouchDB Insecure Default Initialization of Resource Vulnerability

Added Aug 25, 2022Fed. due Sep 15, 2022

Apache Struts

Apache Struts Improper Input Validation Vulnerability

Added Mar 25, 2022Fed. due Apr 15, 2022

Apache Kylin

Apache Kylin OS Command Injection Vulnerability

Added Mar 25, 2022Fed. due Apr 15, 2022
CVE-2017-12615RansomwareCVSS 8.1

Apache Tomcat

Apache Tomcat on Windows Remote Code Execution Vulnerability

Added Mar 25, 2022Fed. due Apr 15, 2022

Products