logo

BitBucket Server At Risk From Command Injection

ID: 9b0e40dd-581a-5923-9ecd-873b1fa96474

STIX ID: report--9b0e40dd-581a-5923-9ecd-873b1fa96474

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-05-21

Date Updated: 2026-07-16

...
...

This report details CVE-2022-36804, a command-injection RCE in Bitbucket Server/Data Center, noting over 1,500 exposed Bitbucket instances (including critical infrastructure organizations), the rapid public distribution and selling of PoCs, and the high likelihood of active exploitation with the potential for code theft and remote shells; it recommends applying vendor patches or mitigation and reducing internet exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.