CVE-2022-26134Active Exploitation(atlassian / confluence_data_center)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for atlassian confluence_data_center systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.

5.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-06-06. Immediately block all internet traffic to and from affected products AND apply the update per vendor instructions [https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html] OR remove the affected products by the due date on the right. Note: Once the update is successfully deployed, agencies can reassess the internet blocking rules.

Weakness type (CWE)
CWE-917

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • confluence_data_center
  • confluence_server

Threat summary

  • Active exploitation appears in 5 classified signals
  • Public PoC is present in monitored signal
  • 10 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 5 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Peaked 8d ago at 2 mentions (2026-02-14); latest day: 1
  • 10 total mentions across 9 days

Affected systems

Vendors
Products
confluence_data_centerconfluence_server

1 version affected across 2 products

Deep dive

Activity timeline10 mentions / 9d
01122Mentions · 2026-02-14: 2Mentions · 2026-02-18: 1Mentions · 2026-02-26: 1Mentions · 2026-03-04: 1Mentions · 2026-03-10: 1Mentions · 2026-03-30: 1Mentions · 2026-04-17: 1Mentions · 2026-06-17: 1Mentions · 2026-08-10: 1PoC Mentioned / Linked · 2026-02-18: 1PoC Mentioned / Linked · 2026-04-17: 1Active Exploitation · 2026-02-14: 2Active Exploitation · 2026-03-04: 1Active Exploitation · 2026-06-17: 1Active Exploitation · 2026-08-10: 1Technical Details · 2026-02-18: 1Technical Details · 2026-02-26: 1Technical Details · 2026-03-10: 1Technical Details · 2026-04-17: 102-1402-1802-2603-0403-1003-3004-1706-1708-10
Signal classification3 categories
Active Exploitation
550.0%
General
330.0%
PoC
220.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-142
Active Exploitation2
2026-02-181
PoC1
2026-02-261
General1
2026-03-041
Active Exploitation1
2026-03-101
General1
2026-03-301
General1
2026-04-171
PoC1
2026-06-171
Active Exploitation1
2026-08-101
Active Exploitation1
Full discourse10 posts
  • Loginsoft Threat Intel@Loginsoft_Intel
    Active Exploitation

    Cytellite recent detection targeting CVE-2022-26134 — Stiftung Erneuerbare Freiheit Visit -- https://cti.loginsoft.com/ip/185.220.101.39 #Loginsoft #Cytellite #Cybersecurity #CVE202226134 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/i2o2osdzMI

    Post summary

    Cytellite reports recent detection of exploitation activity targeting CVE‑2022‑26134, but no PoC, exploit code, or patching information is provided.

    0101041
    19 followersView on X
  • TI Mindmap HUB@ti_mindmap_hub
    Active Exploitation

    🟡 SNOWLIGHT (China): 107 endpoints, 100+ countries. 16 root cPanel takeovers via CVE-2026-41940 — the same bug we flagged unpatched in Issue #15. Four months later: exploited at scale. Also weaponized: Confluence CVE-2022-26134, four years post-disclosure.

    Post summary

    The post reports that CVE-2026-41940 has been actively exploited at scale for root cPanel takeovers; concurrently, CVE-2022-26134 is weaponized, but no PoC, exploit code, patch, or technical details are provided.

    1000043
    18 followersView on X
  • David@davidsheyi
    Active Exploitation

    2/ China's APT41 is notorious for its dual role in cyber espionage & financially motivated attacks. Known for exploiting CVE-2022-26134, it's a versatile threat. #ThreatActors #CyberSecurity

    Post summary

    The post indicates that APT41 is actively exploiting CVE-2022-26134, highlighting real-world use of the vulnerability.

    1000049
    556 followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    Two Atlassian Confluence Server and Data Center zero-day flaws, CVE-2022-26134 and CVE-2023-22515, have been exploited in the wild by multiple actors, according to Rapid7 and Volexity. https://threatcluster.io/cluster/critical-zero-day-vulnerabilities-in-atlassian-confluence-ex-49e124f7

    Post summary

    The text claims that Atlassian Confluence Server and Data Center zero‑day flaws CVE-2022-26134 and CVE-2023-22515 are being actively exploited in the wild by multiple actors.

    0000091
    356 followersView on X
  • Sun4lower@LittleSun4lower
    PoC

    I just completed Atlassian CVE-2022-26134 room on TryHackMe! An interactive lab showcasing the Confluence Server and Data Center un-authenticated RCE vulnerability. https://tryhackme.com/room/cve202226134?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=66457951599dd28bfb000ded #tryhackme via @tryhackme #tryhackme #Learning #Consistency

    Post summary

    The TryHackMe lab demonstrates the Atlassian CVE‑2022‑26134 un‑authenticated RCE in Confluence Server/Data Center, but no exploit instructions, live attacks, or patches are included.

    0000051
    6 followersView on X
  • VampireXRay@VampireXray
    General

    RCE CVE How When Whois And all Interrogative words https://medium.com/@VampireXRay/cve-2022-26134-the-confluence-rce-that-shook-enterprise-security-2b58c5385011

    Post summary

    The text refers to CVE‑2022‑26134 and links to a Medium article discussing the Confluence RCE, but it does not provide specific proof‑of‑concept details, exploit code, or mitigation steps.

    0000081
    52 followersView on X
  • 317ON13_LIRW@ToTo13ru_xakep
    General

    I just completed Atlassian CVE-2022-26134 room on TryHackMe! An interactive lab showcasing the Confluence Server and Data Center un-authenticated RCE vulnerability. https://tryhackme.com/room/cve202226134?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=662fb6411f3680a87baf9e1f #tryhackme via @tryhackme

    Post summary

    The post announces a TryHackMe lab that demonstrates Atlassian CVE‑2022‑26134, an unauthenticated RCE in Confluence, but contains no PoC, exploit tool, active‑exploitation, or patch information.

    0000027
  • Ezekiel@Ezekieluche_
    General

    I just completed Atlassian CVE-2022-26134 room on TryHackMe! An interactive lab showcasing the Confluence Server and Data Center un-authenticated RCE vulnerability. https://tryhackme.com/room/cve202226134?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=67ebda711f4b04b35fd07e05 #tryhackme via @tryhackme

    Post summary

    The post announces completion of a TryHackMe lab that demonstrates Atlassian CVE-2022-26134, an unauthenticated RCE in Confluence Server and Data Center, but provides no exploit code, patch info, or evidence of active exploitation.

    0000052
    13 followersView on X
  • Napa County Corruption 🕵@NapaCorruption
    PoC

    I just completed Atlassian CVE-2022-26134 room on TryHackMe! An interactive lab showcasing the Confluence Server and Data Center un-authenticated RCE vulnerability. https://tryhackme.com/room/cve202226134?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=63d417a8e9eef70044a768b6 #tryhackme via @tryhackme

    Post summary

    The tweet announces completion of a TryHackMe lab that demonstrates the Atlassian CVE‑2022‑26134 unauthenticated RCE vulnerability.

    0000068
    827 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    Active Exploitation

    Cytellite recent detection targeting CVE-2022-26134 — Stiftung Erneuerbare Freiheit Visit -- https://cti.loginsoft.com/ip/185.220.101.39 #Loginsoft #Cytellite #Cybersecurity #CVE202226134 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/W5MGnm6oDt

    Post summary

    The post indicates that activity targeting CVE‑2022‑26134 has been detected, suggesting the vulnerability is being exploited in the wild, but no proof‑of‑concept, exploit code, patch, or technical details are provided.

    0000042
    19 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appatlassianconfluence_data_center---
Appatlassianconfluence_data_center7.18.0--
Appatlassianconfluence_server---
Appatlassianconfluence_server7.18.0--

Explore more