CVE-2023-22527General(atlassian / confluence_data_center)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for atlassian confluence_data_center systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated attacker to achieve RCE on an affected instance. Customers using an affected version must take immediate action. Most recent supported versions of Confluence Data Center and Server are not affected by this vulnerability as it was ultimately mitigated during regular version updates. However, Atlassian recommends that customers take care to install the latest version to protect their instances from non-critical vulnerabilities outlined in Atlassian’s January Security Bulletin.

7.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-02-14. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-74

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • confluence_data_center
  • confluence_server

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-08-24)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
confluence_data_centerconfluence_server

1 version affected across 2 products

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-28: 1Mentions · 2026-07-12: 1Mentions · 2026-08-24: 2PoC Mentioned / Linked · 2026-07-12: 1PoC Mentioned / Linked · 2026-08-24: 1Exploit Tool / Code · 2026-08-24: 1Active Exploitation · 2026-04-28: 1Technical Details · 2026-07-12: 1Technical Details · 2026-08-24: 104-2807-1208-24
Signal classification2 categories
General
250.0%
PoC
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-281
General1
2026-07-121
PoC1
2026-08-242
General1PoC1
Full discourse4 posts
  • Vivek | Cybersecurity@VivekIntel
    General

    wolf-tools — Threat Intel + Detection Rules Pack 🐺⚡ • Vulnerability Scanners Log4Shell Deep Scan (CVE-2021-44228, 45046) Spring4Shell Deep Scan (CVE-2022-22965) • Threat Intelligence YARA, Sigma, Suricata rules + IOCs • Ransomware Coverage Lorenz ransomware artifacts + detection rules • Exploitation Detection CVE-2023-22527 (Confluence → C3RB3R ransomware) • Defense Controls WDAC policy for blocking dual-use app abuse Focused on real detection + hunting, not theory. 🔗 https://github.com/rtkwlf/wolf-tools #ThreatIntel #SOC #BlueTeam #CyberSecurity #DetectionEngineering

    Post summary

    The post advertises a threat intelligence and detection rule pack that includes scanners, rules, and notes detection of active exploitation of CVE-2023-22527 by ransomware, but it does not provide exploit code, patches, or detailed technical information.

    06024251.8K
    16.1K followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: CVE-2023-22527 CVE-2023-22518 CVE-2023-46604 CVE-2024-25600 CVE-2023-41892 ..🧵👇

    Post summary

    The post lists several critical CVE identifiers but provides no additional technical, exploit, or mitigation details.

    1102042
    38 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [EXPLOIT] EGE-CX-hfZ5GTF [CRITICAL/PoC] Linked: CVE-2023-22527 Atlassian Confluence SSTI Injection 🔗 https://exploitgrid.net/exploits/d6a34836-824a-4caf-9a8e-0b86b494fcde

    Post summary

    The post announces a critical Server‑Side Template Injection in Atlassian Confluence (CVE‑2023‑22527), providing a PoC and exploit grid link without evidence of active exploitation or an available patch.

    1000041
    38 followersView on X
  • r0otk3r@r0otk3r
    PoC

    🚨 CVE-2023-22527: Critical 10.0 CVSS Confluence Data Center Unauthenticated RCE https://www.youtube.com/watch?v=ePwQltGQoII #Cybersecurity #Infosec #AppSec #RCE #Atlassian #Confluence #OGNL #CVE202322527 #PoC #EthicalHacking #BugBounty #PatchNow https://t.co/DkZtIgftb2

    Post summary

    The tweet announces CVE-2023-22527 as a critical 10.0 CVSS unauthenticated RCE vulnerability in Atlassian Confluence Data Center, and it shares a proof‑of‑concept through a linked video.

    0001066
    43 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appatlassianconfluence_data_center---
Appatlassianconfluence_data_center8.7.0--
Appatlassianconfluence_server---

Explore more