ThreatCluster[verified]@threatclusterActive Exploitation
Multiple actors are actively exploiting the two Atlassian Confluence zero‑day vulnerabilities CVE‑2022‑26134 and CVE‑2023‑22515, as reported by Rapid7 and Volexity.
Orifha Joan@purpullgirlPoC
The post announces a TryHackMe tutorial that demonstrates how to exploit CVE-2023-22515 to gain admin access in Confluence Server and Data Center editions.
Sun4lower@LittleSun4lowerPoC
User completed a TryHackMe room demonstrating the exploitation of Confluence CVE‑2023‑22515 for admin access.
317ON13_LIRW@ToTo13ru_xakepGeneral
The post announces completion of a TryHackMe room on CVE-2023-22515 and notes the exploit allows admin access to Confluence, but it provides no PoC, exploit code, or patch information.
Roman@mrBr4unExploit
The post promotes a TryHackMe room that teaches how to exploit Confluence CVE‑2023‑22515 for admin access, but it does not provide actual exploit code or evidence of real‑world attacks.
Secwiser - Cyber Security Insights@SecwiserappActive Exploitation
CVE-2023-22515 in Atlassian Confluence allows unauthenticated users to trigger Setup Mode, create a persistent admin account, and gain full control; the vulnerability has been actively exploited via a simple curl request.