Original link: Like burglars closing a door, Apache ActiveMQ attackers patch critical vuln after breaking in / TheRegister.
The vulnerability was fixed in October 2023, but apparently so many have still not patched, that it can still be used.