Atlassian Confluence Servers Hacked via Zero-Day Vulnerability
Organizations have been warned about an unpatched Confluence Server zero-day vulnerability (CVE-2022-26134) that has been exploited in the wild by multiple threat groups.
Stay updated with breaking news from Confluence Server. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
Organizations have been warned about an unpatched Confluence Server zero-day vulnerability (CVE-2022-26134) that has been exploited in the wild by multiple threat groups.
An unpatched remote code execution (RCE) vulnerability in all versions of the popular Confluence collaboration platform can be abused in credential harvesting, cyber espionage, and network backdoor attacks.
Atlassian has issued a critical security warning to users of its Confluence tool after being alerted of an ongoing cyberattack.
Note: There is currently no available patch or fix for the issue described in this blog post. Volexity strongly recommends that all organizations block external access to their Confluence Server instances immediately until an update is provided by Atlassian. Over the Memorial Day weekend in the United States, Volexity conducted an incident response investigation involving two Internet-facing web servers belonging to one of its customers that were running Atlassian Confluence Server software. The investigation began after suspicious activity was detected on the hosts, which included JSP webshel...
Remote code execution, with webshells written to disk.