Atlassian Confluence Server and Data Server Vulnerability is Under Active Exploitation
Critical RCE vulnerability has no security update but workarounds are available
Summary
Critical RCE vulnerability has no security update but workarounds are available
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Atlassian has released a critical advisory that addresses an unauthenticated remote code execution (RCE) vulnerability known as CVE-2022-26134. A remote, unauthenticated attacker could exploit this vulnerability to take control of the system.
Exploitation in the wild
Atlassian has warned that this vulnerability is under active exploitation in the wild.
Threat updates
Remediation advice
Affected organisations are encouraged to review the Atlassian Confluence Security Advisory 2022-06-02 and apply the relevant updates.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 6 June 2022 3:19 pm