Skip to main content

CVE detail

CVE-2022-26134

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.

CVSS 9.8 · CriticalBuzz score 93.0KEV listed5 public exploit repository references

Buzz score

Why this CVE is surfacing

Buzz score total 93.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 18.0
Mention score
30.0
56 evidence mentions in the snapshot
Diversity score
20.0
10 sources across 3 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
18.0
5 repos · best confidence 0.99
Best PoC traction
1253
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
56 source links · newest first
  • A 40-year-old Jordanian man has admitted to selling unauthorized access to computer networks of at least 50 companies, the US Attorney’s Office of the District of New Jersey has announced. Feras Khalil Ahmad Albashiti has pleaded guilty last Thursday to fraud and related activity in connection with access devices. “In May 2023, law enforcement officers were investigating an online forum where malware and malicious code was being offered for sale. Albashiti controlled an online moniker … More →

    newswww.helpnetsecurity.comJan 20, 2026, 1:07 PM
  • A new attack campaign is targeting publicly accessible Docker, Hadoop, Confluence, and Redis deployments by exploiting common misconfigurations and known vulnerabilities. The attackers deploy previously unseen payloads including four binaries written in Golang. “Once initial access is achieved, a series of shell scripts and general Linux attack techniques are used to deliver a cryptocurrency miner, […]

    newswww.csoonline.comMar 6, 2024, 9:42 PM
  • A new malware campaign has been observed targeting misconfigured Apache Hadoop, Confluence, Docker, and Redis instances.

    newswww.securityweek.comMar 6, 2024, 3:50 PM
  • Atlassian has released urgent patches for several of its products to fix remote code execution and denial-of-service vulnerabilities. Flaws in Atlassian products have been exploited by hackers before, including shortly after a patch was released or even before a fix was available. In October, Atlassian released an emergency fix for a broken access control issue […]

    newswww.csoonline.comDec 12, 2023, 8:25 PM
  • Atlassian fixed a critical zero-day flaw in its Confluence Data Center and Server software, which has been exploited in the wild. Software giant Atlassian released emergency security updates to address a critical zero-day vulnerability, tracked as CVE-2023-22515 (CVSS score 10), in its Confluence Data Center and Server software. The flaw CVE-2023-22515 is a privilege escalation vulnerability […]

    newssecurityaffairs.comOct 4, 2023, 7:45 PM
  • Iran-linked Peach Sandstorm APT is behind password spray attacks against thousands of organizations globally between February and July 2023. Microsoft researchers observed a series of password spray attacks conducted by Iran nation-state actors as part of a campaign named Peach Sandstorm (aka Holmium, APT33, Elfin, and Magic Hound). The APT33 group has been around since at least […]

    newssecurityaffairs.comSep 16, 2023, 1:36 PM
  • An Iranian state-operated cyberespionage group has launched password spray attacks against thousands of organizations this year in an attempt to establish persistence into their environments, move laterally, and collect useful intelligence. The targeted organizations were primarily from the satellite, defense, and pharmaceuticals sectors and spanned different geographies. Microsoft tracks the group as Peach Sandstorm, but […]

    newswww.csoonline.comSep 15, 2023, 9:02 PM
  • Top 12 vulnerabilities routinely exploited in 2022Help Net Security

    Cybersecurity agencies from member countries of the Five Eyes intelligence alliance have released a list of the top 12 vulnerabilities routinely exploited in 2022, plus 30 additional ones also “popular” with attackers. The top 12 “In 2022, malicious cyber actors exploited older software vulnerabilities more frequently than recently disclosed vulnerabilities and targeted unpatched, internet-facing systems. Proof of concept (PoC) code was publicly available for many of the software vulnerabilities or vulnerability chains likely facilitating exploitation … More →

    newswww.helpnetsecurity.comAug 4, 2023, 1:17 PM
  • Five Eyes government agencies have published a list of the software vulnerabilities that were most frequently exploited in malicious attacks in 2022.

    newswww.securityweek.comAug 4, 2023, 9:08 AM
  • CISA, the FBI, and NSA, along with Five Eyes cybersecurity agencies published a list of the 12 most exploited vulnerabilities of 2022. CISA, the NSA, and the FBI, in collaboration with cybersecurity authorities from Australia, Canada, New Zealand, and the United Kingdom, have published a list of the 12 most exploited vulnerabilities of 2022. The […]

    newssecurityaffairs.comAug 4, 2023, 6:30 AM
  • Google’s Threat Analysis Group Google states that more than 40% of zero-day flaws discovered in 2022 were variants of previous issues. The popular Threat Analysis Group (TAG) Maddie Stone wrote Google’s fourth annual year-in-review of zero-day flaws exploited in-the-wild [2021, 2020, 2019], it is built off of the mid-year 2022 review. In 2022, the researchers […]

    newssecurityaffairs.comJul 30, 2023, 4:38 PM
  • A new research report discusses the five most exploited vulnerabilities of 2022, and the five key risks that security teams should consider.

    newswww.securityweek.comMar 29, 2023, 11:45 AM
  • Experts warn that 55 zero-day vulnerabilities were exploited in attacks carried out by ransomware and cyberespionage groups in 2022. Cybersecurity firm Mandiant reported that ransomware and cyberespionage groups exploited 55 zero-day flaws in attacks in the wild. Most of the zero-day vulnerabilities were in software from Microsoft, Google, and Apple. The figures show a decrease […]

    newssecurityaffairs.comMar 21, 2023, 3:27 PM
  • 20th February – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 20th February, please download our Threat_Intelligence Bulletin TOP ATTACKS AND BREACHES Check Point Research identified a campaign against entities in Armenia, using a new version of OxtaRAT – an AutoIt-based backdoor for remote access and desktop surveillance. The threat actors have been targeting human […]

    vendorresearch.checkpoint.comFeb 20, 2023, 4:33 PM
  • A new variant of Mirai — the botnet malware used to launch massive DDoS attacks —has been targeting 13 vulnerabilities in IoT devices connected to Linux servers, according to researchers at Palo Alto Networks’ Unit 42 cybersecurity team. Once the vulnerable devices are compromised by the variant, dubbed V3G4, they can fully controlled by attackers […]

    newswww.csoonline.comFeb 17, 2023, 6:04 PM
  • During the second half of 2022, a variant of the Mirai bot, tracked as V3G4, targeted IoT devices by exploiting tens of flaws. Palo Alto Networks Unit 42 researchers reported that a Mirai variant called V3G4 was attempting to exploit several flaws to infect IoT devices from July to December 2022. Below is the list […]

    newssecurityaffairs.comFeb 16, 2023, 9:32 PM
  • A recent variant of the Mirai malware has been observed targeting 13 IoT vulnerabilities to ensnare devices into a botnet.

    newswww.securityweek.comFeb 16, 2023, 1:56 PM
  • We observed Mirai variant V3G4 targeting IoT devices in three separate campaigns in 2022.

    vendorunit42.paloaltonetworks.comFeb 15, 2023, 2:00 PM
  • Bypassing OGNL sandboxes for fun and charitiesGitHub Security Lab

    Object Graph Notation Language (OGNL) is a popular, Java-based, expression language used in popular frameworks and applications, such as Apache Struts and Atlassian Confluence. Learn more about bypassing certain OGNL injection protection mechanisms including those used by Struts and Atlassian Confluence, as well as different approaches to analyzing this form of protection so you can harden similar systems.

    vendorgithub.blogJan 27, 2023, 4:00 PM
  • GreyNoise Intelligence unveiled its research report that dives deep into the most significant threat detection events of the past 12 months. “When it comes to cybersecurity, not all vulnerabilities are created equal, and many of the ones that garner media attention actually turn out to be insignificant,” said Bob Rudis, VP Research & Data Science, GreyNoise Intelligence. GreyNoise added over 230 new detection tags in 2022, representing an increase of approximately 38% from 2021. For … More →

    newswww.helpnetsecurity.comJan 2, 2023, 4:00 AM
  • Microsoft warns of an uptick among threat actors increasingly using publicly-disclosed zero-day exploits in their attacks. According to the Digital Defense Report published by Microsoft, threat actors are increasingly leveraging publicly-disclosed zero-day vulnerabilities to target organizations worldwide. The researchers noticed a reduction in the time between the announcement of a vulnerability and the commoditization of […]

    newssecurityaffairs.comNov 5, 2022, 5:30 PM
  • Security Affairs newsletter Round 385Security Affairs

    A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs free for you in your email box. If you want to also receive for free the newsletter with the international press subscribe here. ISC fixed high-severity flaws in the BIND DNS software Ukraine: SSU dismantled cyber gang that stole […]

    newssecurityaffairs.comSep 25, 2022, 10:10 AM
  • Threat actors are targeting unpatched Atlassian Confluence servers as part of an ongoing crypto mining campaign. Trend Micro researchers warn of an ongoing crypto mining campaign targeting Atlassian Confluence servers affected by the CVE-2022-26134 vulnerability. The now-patched critical security flaw was disclosed by Atlassian in early June, at the time the company warned of a […]

    newssecurityaffairs.comSep 22, 2022, 11:06 AM
  • Deep learning models can help defenders improve zero-day exploit detection. We provide case studies focused on command injection and SQL injection.

    vendorunit42.paloaltonetworks.comSep 16, 2022, 1:00 PM
  • A new report from Trustwave SpiderLabs has revealed that the number of CVEs published so far this year could be as much as 35% higher than in the same period in 2021. The findings come from the security firm’s 2022 Telemetry Report. While organizations appear to be exhibiting greater awareness of effective patch management compared […]

    newswww.csoonline.comAug 25, 2022, 2:06 PM
  • A cybersecurity analysis of hundreds of media industry vendors showed that many companies are slow to patch critical vulnerabilities, according to MDR and third-party risk management provider BlueVoyant.

    newswww.securityweek.comAug 22, 2022, 1:14 PM
  • A threat actor, tracked as TAC-040, exploited Atlassian Confluence flaw CVE-2022-26134 to deploy previously undetected Ljl Backdoor. Cybersecurity firm Deepwatch reported that a threat actor, tracked as TAC-040, has likely exploited the CVE-2022-26134 flaw in Atlassian Confluence servers to deploy a previously undetected backdoor dubbed Ljl Backdoor. The attackers exploited the flaw in an attack […]

    newssecurityaffairs.comAug 5, 2022, 8:49 AM
  • The crimeware group known as 8220 Gang expanded over the last month their Cloud Botnet to roughly 30,000 hosts globally. Researchers from SentinelOne reported that low-skill crimeware 8220 Gang has expanded their Cloud Botnet over the last month to roughly 30,000 hosts globally. The gang focuses on infecting cloud hosts to deploy cryptocurrency miners by […]

    newssecurityaffairs.comJul 21, 2022, 8:06 AM
  • 4th July – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 4th July, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Iranian steel manufacturing plants have suffered a cyberattack which reportedly forced them to halt production. The hacker group Gonjeshke Darande, which has previously attacked the Iranian railway system, assumed responsibility for the […]

    vendorresearch.checkpoint.comJul 4, 2022, 11:28 AM
  • Software firm Atlassian released emergency patches for its popular Confluence Server and Data Center products after reports came to light late last week that attackers were exploiting an unpatched vulnerability in the wild. According to data from Cloudflare’s web application firewall (WAF) service, the attacks started in late May. The vulnerability, now tracked as CVE-2022-26134, […]

    newswww.csoonline.comJul 4, 2022, 9:00 AM
  • Google Project Zero states that in H1 2022 at least half of zero-day issues exploited in attacks were related to not properly fixed old flaws. Google Project Zero researcher Maddie Stone published a blog post that resumes her speech at the FIRST conference in June 2022, the presentation is titled “0-day In-the-Wild Exploitation in 2022…so […]

    newssecurityaffairs.comJul 3, 2022, 1:31 PM
  • Microsoft spotted a cloud threat actor tracked as 8220 that is now targeting Linux servers in a long-running cryptomining campaign. Microsoft Security Intelligence experts are warning of a long-running campaign conducted by a cloud threat actor group, tracked as 8220, that is now targeting Linux servers to install crypto miners. “We observed notable updates to […]

    newssecurityaffairs.comJul 1, 2022, 2:44 PM
  • Google Project Zero has observed a total of 18 exploited zero-day vulnerabilities in the first half of 2022, at least half of which exist because previous bugs were not properly addressed.

    newswww.securityweek.comJul 1, 2022, 11:12 AM
  • A threat actor is selling access to 50 vulnerable networks that have been compromised exploiting the recently disclosed Atlassian Confluence zero-day. A threat actor is selling access to 50 vulnerable networks that have been compromised by exploiting the recently discovered Atlassian Confluence zero-day flaw (CVE-2022-26134). The discovery was made by the Rapid7 Threat Intelligence team […]

    newssecurityaffairs.comJun 26, 2022, 6:27 PM
  • A new round of the weekly Security Affairs newsletter arrived! Every week the best security articles from Security Affairs for free in your email box. If you want to also receive for free the newsletter with the international press subscribe here. US DoJ announced to have shut down the Russian RSOCKS Botnet MaliBot Android Banking Trojan […]

    newssecurityaffairs.comJun 20, 2022, 12:12 PM
  • China-linked threat actors exploited the zero-day flaw CVE-2022-1040 in Sophos Firewall weeks before it was fixed by the security vendor. Volexity researchers discovered that the zero-day vulnerability, tracked as CVE-2022-1040, in Sophos Firewall was exploited by Chinese threat actors to compromise a company and cloud-hosted web servers it was operating. The vulnerability was exploited by […]

    newssecurityaffairs.comJun 17, 2022, 11:00 PM
  • According to Volexity, a webshell was discovered in Atlassian Confluence server during an incident response investigation. Volexity determined that it was a zero-day vulnerability that could execute remote code even after the latest patch was completed and reported the issue to Atlassian. After receiving the issue report and identifying it as a zero-day, Atlassian issued a security advisory for the critical unauthenticated remote code execution. Timeline (based on PDT) May 31: Volexity found zero-day vulnerability … More →

    newswww.helpnetsecurity.comJun 17, 2022, 5:00 AM
  • Microsoft has warned that “multiple adversaries and nation-state actors” are making use of the recent Atlassian Confluence RCE vulnerability. A fix…

    newswww.malwarebytes.comJun 13, 2022, 5:00 PM
  • 13th June – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 13th June, please download our Threat Intelligence Bulletin. Top Attacks and Breaches The Italian municipality of Palermo has been victim of a ransomware attack that caused a large-scale service outage affecting over a million people. The attack was claimed by the Vice Society ransomware […]

    vendorresearch.checkpoint.comJun 13, 2022, 1:00 PM
  • A recently patched Confluence Server vulnerability is being exploited by multiple cybercrime and state-sponsored threat groups, according to Microsoft.

    newswww.securityweek.comJun 13, 2022, 11:09 AM
  • A new round of the weekly Security Affairs newsletter arrived! Every week the best security articles from Security Affairs for free in your email box. If you want to also receive for free the newsletter with the international press subscribe here. Ransomware gangs are exploiting CVE-2022-26134 RCE in Atlassian Confluence servers HID Mercury Access Controller flaws […]

    newssecurityaffairs.comJun 12, 2022, 10:21 PM
  • Ransomware gangs are actively exploiting CVE-2022-26134 remote code execution (RCE) flaw in Atlassian Confluence Server and Data Center. Multiple ransomware groups are actively exploiting the recently disclosed remote code execution (RCE) vulnerability, tracked as CVE-2022-26134, affecting Atlassian Confluence Server and Data Center. Proof-of-concept exploits for the CVE-2022-26134 vulnerability have been released online, Bleeping Computer reported that starting from […]

    newssecurityaffairs.comJun 12, 2022, 2:14 PM
  • Threat actors are exploiting the recently disclosed CVE-2022-26134 RCE in Atlassian Confluence servers to deploy cryptocurrency miners. CheckPoint researchers have observed threat actors exploiting the recently disclosed CVE-2022-26134 remote code execution vulnerability in Atlassian Confluence servers to deploy cryptocurrency miners. Last week, Atlassian warned of a critical unpatched remote code execution vulnerability affecting all Confluence […]

    newssecurityaffairs.comJun 10, 2022, 8:51 PM
  • Horizon3.ai experts were in the news this week on topics ranging from the future of penetration testing, the Atlassian Confluence flaw, AI.

    exploithorizon3.aiJun 10, 2022, 6:41 PM
  • CPO Magazine: 06/9/22 As Naveen Sunkavalley, Chief Architect at Horizon3.ai, notes: “CVE-2022-26134 is about as bad as it gets. The vulnerability is easy to scan for and easy to exploit using a single HTTP GET request … Confluence instances often contain a wealth of user data and business-critical information that is valuable for attackers moving laterally […]

    exploithorizon3.aiJun 9, 2022, 7:28 PM
  • Threatpost: 06/7/22 “CVE-2022-26134 is about as bad as it gets,” observed Naveen Sunkavalley, chief architect of security firm Horizon3.ai, in an email to Threatpost. Key issues are that the vulnerability is quite easy both to find and exploit, with the latter possible using a single HTTP GET request, he said. Read the entire article here

    exploithorizon3.aiJun 7, 2022, 7:34 PM
  • 6th June – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 6th June, please download our Threat Intelligence Bulletin. Top Attacks and Breaches An unaffiliated threat actor has been initialing a phishing campaign targeting government entities in Europe and the U.S, exploiting the recently disclosed Microsoft Office “Follina” vulnerability, tracked CVE-2022-30190. Check Point IPS, Threat […]

    vendorresearch.checkpoint.comJun 6, 2022, 4:46 PM
  • nternet security firm GreyNoise said the number of unique IP addresses launching attacks using the RCE flaw, tracked as CVE-2022-26134, has risen from 28 to 400 since Friday when exploitation began. US officials warn of “mass exploitation” of Atlassian Confluence flaw Atlassian patches One-Click flaw that allowed hackers to steal user sessions Atlassia

    newswww.itpro.comJun 6, 2022, 10:52 AM
  • Atlassian informed customers on Friday that it has released patches for the critical Confluence Server vulnerability that has been exploited in attacks. The announcement came just before cybersecurity organizations warned that exploitation attempts have spiked.

    newswww.securityweek.comJun 6, 2022, 10:02 AM
  • Proof-of-concept exploits for the critical CVE-2022-26134 vulnerability in Atlassian Confluence and Data Center servers are available online. Proof-of-concept exploits for the critical CVE-2022-26134 flaw, affecting Atlassian Confluence and Data Center servers, have been released. Bleeping Computer reported that starting from Friday afternoon, a proof-of-concept exploit for this issue was publicly shared. Researchers from cybersecurity firm […]

    newssecurityaffairs.comJun 5, 2022, 6:11 PM
  • Atlassian has addressed on Friday an actively exploited critical remote code execution flaw (CVE-2022-26134) in Confluence Server and Data Center products. Early this week, Atlassian warned of a critical unpatched remote code execution vulnerability affecting all Confluence Server and Data Center supported versions, tracked as CVE-2022-26134, that is being actively exploited in attacks in the […]

    newssecurityaffairs.comJun 5, 2022, 9:51 AM
  • Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Zero-day bug exploited by attackers via macro-less Office documents (CVE-2022-30190) A newly numbered Windows zero-day vulnerability (CVE-2022-30190) is being exploited in the wild via specially crafted Office documents (without macros), security researchers are warning. And a variety of attackers have started leveraging it. FluBot takedown: Law enforcement takes control of Android spyware’s infrastructure An international law enforcement operation involving 11 … More →

    newswww.helpnetsecurity.comJun 5, 2022, 8:00 AM
  • CVE-2022-26134 is a critical severity unauthenticated remote code execution vulnerability in Atlassian Confluence Server and Data Center. We share statistics on potentially vulnerable servers and provide suggestions for mitigation.

    vendorunit42.paloaltonetworks.comJun 4, 2022, 12:00 AM
  • A critical zero-day vulnerability (CVE-2022-26134) in Atlassian Confluence Data Center and Server is under active exploitation, the software maker has warned on Thursday. There is currently no fix available – though they are expected to be released today (Friday) – and users of the popular enterprise collaboration solution are advised to either temporarily restrict access to Confluence Server and Data Center instances from the internet, or to disable them completely. “If you are unable to … More →

    newswww.helpnetsecurity.comJun 3, 2022, 10:13 AM
  • Atlassian warned of an actively exploited critical unpatched remote code execution flaw (CVE-2022-26134) in Confluence Server and Data Center products. Atlassian is warning of a critical unpatched remote code execution vulnerability affecting all Confluence Server and Data Center supported versions, tracked as CVE-2022-26134, that is being actively exploited in attacks in the wild. “Atlassian has […]

    newssecurityaffairs.comJun 3, 2022, 10:13 AM
  • Atlassian scrambling to patch Confluence Server zero-day exploited by multiple threat groups Atlassian customers have been warned that hackers are exploiting a Confluence Server zero-day vulnerability. The flaw is currently unpatched and it appears to have been exploited by multiple threat groups.

    newswww.securityweek.comJun 3, 2022, 10:00 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

5 repository references · best confidence 0.99 · max 1253 stars

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence