Critical Zero-Day Vulnerabilities in Atlassian Confluence Exploited

Critical Zero-Day Vulnerabilities in Atlassian Confluence Exploited

First seen 17 Jun 2026, 12:42 UTC Rapid7www.volexity.comconfluence.atlassian.comowasp.orggithub.com 88% similarity 72.9

Article Content

Browse articles
ThreatCluster

Atlassian Confluence has faced multiple critical vulnerabilities, including CVE-2022-26134 and CVE-2023-22515. CVE-2022-26134, published on June 3, 2022, is an unauthenticated remote code execution vulnerability that has been actively exploited. CVE-2023-22515, disclosed on October 4, 2023, allows unauthenticated attackers to create new administrator accounts, leading to severe data integrity risks. Both vulnerabilities affect Confluence Server and Data Center. The exploitation of these vulnerabilities has been confirmed in the wild, prompting urgent advisories for organizations to apply patches or implement workarounds. The vulnerabilities are particularly dangerous for internet-facing instances of Confluence. Security firms have observed multiple actors exploiting these vulnerabilities, emphasizing the need for immediate action. Organizations are advised to restrict access to vulnerable systems until they are patched.

Key Points: • CVE-2022-26134 allows remote code execution and has been actively exploited since June 2022. • CVE-2023-22515 enables unauthenticated attackers to create administrator accounts, posing a severe risk. • Organizations must apply patches or restrict access to vulnerable Confluence instances immediately.

ThreatCluster AI How this analysis works

Timeline

2018-08-22
CVE-2018-11776 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2021-08-30
CVE-2021-26084 published
An unauthenticated remote OGNL injection vulnerability in Confluence Server was disclosed.
Rapid7
2022-03-08
CVE-2022-26314 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2022-06-02
CVE-2022-26134 added to CISA KEV
CISA confirmed active exploitation of CVE-2022-26134 in the wild.
Rapid7
2022-06-03
CVE-2022-26134 published
Atlassian released a critical remote code execution vulnerability affecting Confluence.
Rapid7
2023-10-04
CVE-2023-22515 published
Atlassian disclosed a critical vulnerability allowing unauthenticated access to create admin accounts.
Rapid7
2023-10-05
CVE-2023-22515 added to CISA KEV
CISA confirmed active exploitation of CVE-2023-22515 shortly after its disclosure.
Rapid7

Community

Browse all →