logo

Critical Zero-Day Vulnerabilities in Atlassian Confluence Exploited

ID: 788266c4-389a-535b-9c50-585e6f692209

STIX ID: report--788266c4-389a-535b-9c50-585e6f692209

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-06-17

Date Updated: 2026-06-22

...
...

Atlassian Confluence Server and Data Center are affected by two critical vulnerabilities — CVE-2022-26134 (unauthenticated RCE, actively exploited since June 2022) and CVE-2023-22515 (unauthenticated creation of admin accounts, disclosed October 2023) — with confirmed exploitation in the wild; organizations are urgently advised to apply patches or restrict access to internet-facing instances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.