Critical Zero-Day Vulnerabilities in Atlassian Confluence Exploited
ID: c8499703-e026-5e30-9383-aa6c251051bf
STIX ID: report--c8499703-e026-5e30-9383-aa6c251051bf
Feed Name: ThreatCluster
Threat Score
Atlassian Confluence is affected by two critical unauthenticated vulnerabilities: CVE-2022-26134 (remote code execution, exploited since June 2022) and CVE-2023-22515 (allows creation of new administrator accounts, disclosed October 4, 2023). Both impact Server and Data Center, have been confirmed exploited in the wild by multiple actors, and organizations are urged to patch or restrict access to internet-facing instances immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
