Atlassian Confluence OGNL RCE Vulnerability

Released: Jun 04, 2022


High Severity

Confluence Platform

Atlassian Vendor

Vulnerability Type


A critical vulnverability on Atlassian Confluence

A critical 0-day vulnerability on Atlassian Confluence Data Center and Server is actively being exploited in the wild. The vulnerability is established via the Object Graph Navigation Language (OGNL) injection that allows an unauthenticated user to execute arbitrary code. Learn More »

Common Vulnerabilities and Exposures

CVE-2022-26134

Background

A cybersecurity firm Volexity was responding to an attack incident, which revealed that the attack leveraged a 0-day vulnerability on Atlassian Confluence Server.

Latest Development

Recent news and incidents related to cybersecurity threats encompassing various events such as data breaches, cyber-attacks, security incidents, and vulnerabilities discovered.


June 2, 2022: The vendor has released an advisory.


June 2, 2022: The Hacker News posted an article on Volexity's discovery of the 0-day.
June 3, 2022: The vendor has released their fixed.

FortiGuard Cybersecurity Framework

Mitigate security threats and vulnerabilities by leveraging the range of FortiGuard Services.


PROTECT
  • Vulnerability

  • IPS

  • Post-execution

DETECT
  • Threat Hunting

RESPOND
  • Assisted Response Services

  • Automated Response

RECOVER
  • NOC/SOC Training

  • End-User Training

IDENTIFY
  • Attack Surface Hardening

  • Vulnerability Management

Threat Intelligence

Information gathered from analyzing ongoing cybersecurity events including threat actors, their tactics, techniques, and procedures (TTPs), indicators of compromise (IOCs), malware and related vulnerabilities.


Loading ...

Indicators of compromise Indicators of compromise
IOC Threat Activity

Last 30 days

Chg

Avg 0