Hazard

Is CVE-2022-26134 being exploited?

Ransomware crews are using this

CISA has linked this vulnerability to known ransomware campaigns. Treat any exposed instance as an active incident, not a patching ticket.

Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability

Atlassian · Confluence Server/Data Center

CVSS 9.8 EPSS 100% 1 public exploit ransomware Fix deadline passed 6 June 2022

What it is

Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution.

Why we say that

  • Linked by CISA to known ransomware campaigns
  • EPSS puts exploitation in the next 30 days at 100%
  • 1 public exploit published
  • CISA's federal remediation deadline (2022-06-06) has passed
  • CVSS 9.8 critical
  • Listed in the CISA Known Exploited Vulnerabilities catalogue

Every line above comes from a named public source. Where the evidence is thin, we say so rather than inventing confidence — see methodology.

What to do

Immediately block all internet traffic to and from affected products AND apply the update per vendor instructions [https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html] OR remove the affected products by the due date on the right. Note: Once the update is successfully deployed, agencies can reassess the internet blocking rules.

Public exploit code

Indexed from Exploit-DB. Presence of code raises urgency; absence does not mean safety.

What it costs when this goes wrong

This is where UK enforcement meets the vulnerability record. This vulnerability is used in ransomware campaigns; here is what ransomware has cost UK organisations at the regulator.

All UK cases caused by ransomware →