vimarsana.com

Page 15 - Confluence Server News Today : Breaking News, Live Updates & Top Stories | Vimarsana

Atlassian issues security alert to users of its Confluence software

Atlassian has issued a critical security warning to users of its Confluence tool after being alerted of an ongoing cyberattack.

Zero-Day Exploitation of Atlassian Confluence

Note: There is currently no available patch or fix for the issue described in this blog post. Volexity strongly recommends that all organizations block external access to their Confluence Server instances immediately until an update is provided by Atlassian. Over the Memorial Day weekend in the United States, Volexity conducted an incident response investigation involving two Internet-facing web servers belonging to one of its customers that were running Atlassian Confluence Server software. The investigation began after suspicious activity was detected on the hosts, which included JSP webshells being written to disk. Volexity immediately used Volexity Surge Collect Pro to collect system memory and key files from the Confluence Server systems for analysis. After a thorough review of the collected data, Volexity was able to determine the server compromise stemmed from an attacker launching an exploit to achieve remote code execution. Volexity was subsequently able to recreate that explo

No patch for actively exploited Atlassian Confluence zero-day

Atlassian: There is a critical RCE flaw in Confluence, so block internet access ASAP

Some IT admins may be in for a scare this weekend as Atlassian has warned of a critical RCE flaw affecting all Confluence Server and Data Center versions. Internet access should be restricted ASAP.

© 2025 Vimarsana

vimarsana © 2020. All Rights Reserved.