Patch Now: Atlassian Confluence Bug Under Active Exploit
Attackers almost immediately leapt on a just-disclosed bug, CVE-2022-26138, affecting Atlassian Confluence, which allows remote, unauthenticated actors unfettered access to Confluence data.
Stay updated with breaking news from Confluence Server. Get real-time updates on events, politics, business, and more. Visit us for reliable news and exclusive interviews.
Attackers almost immediately leapt on a just-disclosed bug, CVE-2022-26138, affecting Atlassian Confluence, which allows remote, unauthenticated actors unfettered access to Confluence data.
CVE-2022-26138 is the second major vulnerability disclosure made for Atlassian’s Confluence collaboration platform in recent months.
A hardcoded password associated with the Questions for Confluence app has been publicly released, which will likely lead to exploit attempts that give cyberattackers access to all Confluence content.
Patches have been issued, and users have been warned
Atlassian has disclosed yet another critical severity flaw in Confluence. The latest issue is very trivial to exploit as it involves leveraging hardcoded credentials to get wide access to Confluence.