Skip to main content

Atlassian Confluence Server and Data Server Vulnerability is Under Active Exploitation

Critical RCE vulnerability has no security update but workarounds are available

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Critical RCE vulnerability has no security update but workarounds are available


Threat details

Introduction

Atlassian has released a critical advisory that addresses an unauthenticated remote code execution (RCE) vulnerability known as CVE-2022-26134. A remote, unauthenticated attacker could exploit this vulnerability to take control of the system.

Exploitation in the wild

Atlassian has warned that this vulnerability is under active exploitation in the wild.


Threat updates

Date Update
6 Jun 2022 Patch Releases

Atlassian has released security updates addressing a critical RCE vulnerability affecting its Confluence Server and Data Center products. This vulnerability has been actively exploited by threat actors to achieve remote code execution.


Remediation advice

Affected organisations are encouraged to review the Atlassian Confluence Security Advisory 2022-06-02 and apply the relevant updates.



Last edited: 6 June 2022 3:19 pm