logo

Apache OFBiz RCE flaw exploited to find vulnerable Confluence servers

ID: 76b3f333-74f0-52eb-9385-0732fa55fe6b

STIX ID: report--76b3f333-74f0-52eb-9385-0732fa55fe6b

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2023-12-28

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A critical pre-authentication RCE in Apache OFBiz (CVE-2023-49070) was actively exploited using public PoCs; an attempted fix left a root cause allowing an additional bypass (CVE-2023-51467) until Apache released OFBiz 18.12.11. Security researchers and monitoring services report widespread scanning and exploitation attempts targeting vulnerable servers (including Confluence instances), and administrators are urged to upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.