CVE-2021-26084
ID: 58088651-3436-5d6f-a8d9-35d602cf302f
STIX ID: report--58088651-3436-5d6f-a8d9-35d602cf302f
Feed Name: Arctic Wolf Blog
Atlassian disclosed CVE-2021-26084, a critical (CVSS 9.8) OGNL injection vulnerability in Confluence Server that allows unauthenticated remote code execution across multiple affected versions; Atlassian released patches on August 25, 2021 and later confirmed the issue is exploitable without authentication and has been observed in the wild, with threat actors deploying crypto-miners. Organizations running on-premises Confluence are advised to verify versions and apply patches immediately to prevent further abuse and potential escalation to other attacks such as ransomware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
