logo

Zero-Day Exploitation of Atlassian Confluence

ID: e0d657a1-c508-5f57-afec-1ee4ba8a11f9

STIX ID: report--e0d657a1-c508-5f57-afec-1ee4ba8a11f9

Feed Name: Volexity Blog

Threat Score
90/100

Date Published: 2022-06-02

Date Updated: 2026-05-01

...
...

Volexity investigated active exploitation of a zero-day remote code execution vulnerability in Atlassian Confluence (CVE-2022-26134), identifying an in-memory BEHINDER implant and disk-based webshells (China Chopper and a custom upload shell), recovered attacker commands and IOCs (file hashes and multiple IPs), provided forensic analysis and detection guidance, and recommended immediate patching and mitigation steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.