logo

Patch ASAP: Max-Critical Atlassian Bug Allows Unauthenticated RCE

ID: 2e5568e8-a9a2-5abe-9be0-74fece630e0b

STIX ID: report--2e5568e8-a9a2-5abe-9be0-74fece630e0b

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-01-16

Date Updated: 2026-04-21

Author: Tara Seals, Managing Editor, News, Dark Reading

...
...

Executive summary: A max-critical unauthenticated remote code execution vulnerability (CVE-2023-22527, CVSSv3=10) affects multiple Atlassian Confluence Server and Data Center versions (notably 8.0.x–8.5.3 and some EOL releases). Atlassian released patches in its December update; there are no mitigations or workarounds, cloud instances are unaffected, and administrators are advised to immediately apply updates or remove affected instances from Internet exposure and monitor for malicious activity due to significant risk of exploitation for ransomware and espionage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.