logo

Hackers start exploiting critical Atlassian Confluence RCE flaw

ID: bcc828ad-49c7-5a60-b5d5-d1664db41c35

STIX ID: report--bcc828ad-49c7-5a60-b5d5-d1664db41c35

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-01-22

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Executive summary:** Security researchers and Shadowserver report active exploitation of the critical Confluence template-injection RCE CVE-2023-22527 affecting Confluence Server/Data Center versions released before December 5, 2023; Shadowserver recorded over 39,000 exploitation attempts from ~600 IPs against publicly reachable Confluence instances (about 11,100 detected), and Atlassian has released fixed versions (8.5.4, 8.6.0, 8.7.1 and later) — administrators should patch immediately and treat outdated instances as potentially compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.