logo

Atlassian Confluence Server RCE attacks underway from 600+ IPs

ID: d7ab6611-16ca-5df5-96d4-a1d6128d9c9a

STIX ID: report--d7ab6611-16ca-5df5-96d4-a1d6128d9c9a

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2024-01-22

Date Updated: 2026-04-26

Author: Jessica Lyons Hardcastle

...
...

Security organisations Shadowserver and GreyNoise report thousands of RCE exploit attempts against CVE-2023-22527 — a critical (CVSS 10) unauthenticated template-injection vulnerability in Atlassian Confluence Server and Data Center — with more than 600 attacking IPs observed and over 11,000 vulnerable instances exposed online; vendors and researchers urge immediate patching, threat hunting, and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.