U.S. Cyber Command Warns Active Exploitation of Atlassian Confluence Vulnerability

Date:

Share post:

Organizations in the U.S. continue to sustain series of unpatched vulnerability exploits. The U.S. Cyber Command (USCYBERCOM) recently warned organizations to patch the actively exploiting Atlassian Confluence critical vulnerability CVE-2021-26084 immediately.

“Mass exploitation of Atlassian Confluence CVE-2021-26084 is ongoing and expected to accelerate. Please patch immediately if you haven’t already — this cannot wait until after the weekend,” USCYBERCOM said.

Atlassian Confluence Vulnerability

The CVE-2021-26084 vulnerability is an Object-Graph Navigation Language (OGNL) injection flaw that affects Atlassian Confluence Servers and Confluence Data Center software installed on Confluence self-hosted project management platforms. The vulnerability enables an unauthenticated hacker to execute arbitrary code on Confluence Server or Data Center installations.

The vulnerability was discovered by Benny Jacob (SnowyOwl) in the Atlassian public bug bounty program.

Affected versions include:

  • version < 6.13.23
  • 14.0 ≤ version < 7.4.11
  • 5.0 ≤ version < 7.11.5
  • 12.0 ≤ version < 7.12.5

Atlassian Releases Patch

In a security advisory, Atlassian detailed the severity and impacts of the vulnerability. It said, “The vulnerability is being actively exploited in the wild. Affected servers should be patched immediately. The vulnerability is exploitable by unauthenticated users regardless of configuration.”

Atlassian recommended organizations identify vulnerable devices and update them to the latest Long Term Support release to avoid potential risks.

What the Experts Say…

The latest warning from the U.S. Cyber Command created a buzz in the cybersecurity community. Security experts from threat intelligence firm Bad Packets claimed it has identified a mass exploit activity targeting vulnerable Atlassian Confluence servers across the U.S., Brazil, Hong Kong, China, Nepal, Romania, and Russia.

Also, security firm Censys that it detected over 14,701 services that self-identified as a Confluence server. Of those, 13,596 ports and 12,876 individual IPv4 hosts are running an exploitable version of the software.

Subscribe

Name(Required)
Privacy(Required)

Upcoming Events

Related articles

CyberSec Delhi Conference 2026

Securing India’s Power, Defence, Manufacturing & Industrial Ecosystems The CyberSec Delhi Conference 2026 will bring together policymakers, government stakeholders,...

SBOM, VEX, and AI: Dr. Allan Friedman on the Future of Software Supply Chain Security

A conversation on why software transparency is no longer optional, and how AI is about to make it...

Model-Borne Consequence: Why OT Security and Data Security Just Became the Same Job

For thirty years we told you industrial cybersecurity was fundamentally different from IT cybersecurity. We were right. Then...

Truth, Transparency, and a Subpoena: Inside TikTok’s Security Crisis with Roland Cloutier

How the former ByteDance CISO led a 3-billion-user platform through congressional hearings, an international ban threat, and the...