Skip to main content
CISA Known Exploited Vulnerabilities

Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.

Added to KEV
2022-06-02
Remediation due
2022-06-06
Ransomware
Known use

Required action
Immediately block all internet traffic to and from affected products AND apply the update per vendor instructions [https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html] OR remove the affected products by the due date on the right. Note: Once the update is successfully deployed, agencies can reassess the internet blocking rules.

CISA notes
https://nvd.nist.gov/vuln/detail/CVE-2022-26134

Description

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.

Severity

CVSS 3.1 · CISA9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC · CISA-ADP
Exploitationactive
Automatableyes
Technical impacttotal

Affected Products

VendorProductAffected versions
AtlassianConfluence Data Center
next of 1.3.0 to <unspecified
unspecified to <7.4.17
7.13.0 to <unspecified
unspecified to <7.13.7
7.14.0 to <unspecified
unspecified to <7.14.3
7.15.0 to <unspecified
unspecified to <7.15.2
7.16.0 to <unspecified
unspecified to <7.16.4
7.17.0 to <unspecified
unspecified to <7.17.4
7.18.0 to <unspecified
unspecified to <7.18.1
AtlassianConfluence Server
next of 1.3.0 to <unspecified
unspecified to <7.4.17
7.13.0 to <unspecified
unspecified to <7.13.7
7.14.0 to <unspecified
unspecified to <7.14.3
7.15.0 to <unspecified
unspecified to <7.15.2
7.16.0 to <unspecified
unspecified to <7.16.4
7.17.0 to <unspecified
unspecified to <7.17.4
7.18.0 to <unspecified
unspecified to <7.18.1

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.