A critical remote code execution vulnerability was found in Atlassian Confluence Server and Data Center with a CVSS score of 9.8 (Critical). CVE-2022-26134 is an OGNL injection vulnerability that a malicious threat actor can exploit to run arbitrary commands in a target Confluence Server or Data Center. Since the vulnerability affects all versions released before the vulnerability’s discovery, organizations are advised to update their Confluence Server and Data Center as soon as possible. For detailed information, visit our blog posts.
June’s Threat Actors
ToddyCat Threat Group
Picus Threat ID: 311440,262389,882906
Target Regions: Taiwan, Viet Nam, Afghanistan, India, Iran Islamic Republic of, Malaysia, Pakistan, Russian Federation, Slovakia, Thailand, United Kingdom of Great Britain and Northern Ireland
Target Regions: Taiwan, Viet Nam, Afghanistan, India, Iran Islamic Republic of,Malaysia, Pakistan, Russian Federation, Slovakia, Thailand, United Kingdom of Great Britain and Northern Ireland
Target Industries: All
Web Application Attacks Atlassian Confluence Data Center Remote Code Execution Vulnerability
Picus Threat ID: 890767
OWASP Top 10: A3 – Injection
CVSS 3 Base Score: 9.8 Critical
CVE: CVE-2022-26134
Affected Product: Atlassian Confluence Data Center
Zimbra CRLF Injection in Memcached Lookups Vulnerability
The SIGRed vulnerability allows an attacker to execute remote commands on Windows operating systems via DNS and it can be spread throughout the networ...