Attackers actively exploited Atlassian Confluence vulnerability CVE-2022-26134, a critical unauthenticated remote code execution flaw caused by OGNL injection, against on-premises Confluence Server and Data Center systems. Volexity first reported in-the-wild exploitation, and Atlassian confirmed that all supported self-managed versions prior to patched releases were affected, while Atlassian Cloud was not vulnerable. Atlassian issued fixed versions including 7.4.17, 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4, and 7.18.1, and also published temporary mitigation steps for organizations unable to patch immediately.
Follow-on attacks used the exploit’s in-memory shell to deliver a wide range of payloads on both Linux and Windows servers, including Gafgyt/Mirai-like botnets, Monero cryptominers, z0miner, Cobalt Strike shellcode, web shells, and a malicious Linux package dubbed pwnkit. Sophos also observed attempts to deploy Cerber ransomware on Windows systems using curl and encoded PowerShell to fetch a payload from the %temp% directory, while Barracuda reported sustained exploitation months after disclosure, with automated reconnaissance, architecture-specific malware downloaders, and some malicious infrastructure remaining online for extended periods.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
After disclosure and proof-of-concept publication, Barracuda observed large numbers of exploitation attempts ranging from reconnaissance to malware delivery. It said the attack pattern continued through the summer, with only a slight drop in overall volume by August.
On June 2, 2022, Atlassian published a security advisory for Confluence Server and Data Center, confirmed active exploitation, released fixed versions, and provided temporary mitigation steps for customers unable to upgrade immediately.
On June 2, 2022, Volexity coordinated disclosure of CVE-2022-26134, an Atlassian Confluence remote code execution vulnerability that was already under active exploitation in the wild.
Barracuda reported that the earliest URLhaus submissions for an IP serving Gafgyt malware dated to late May 2022, indicating the malicious infrastructure used in later Confluence exploitation had been active for months.
Barracuda detailed multiple payload chains delivered via CVE-2022-26134, including a shell script that fetched architecture-specific Gafgyt binaries, a Windows Monero cryptominer chain that disabled Defender, and a likely Linux cryptominer payload. The report also noted some of the malicious infrastructure remained online at the time of writing.
Sophos tracked several attacks against vulnerable Windows and Linux Confluence servers, including two Windows incidents where attackers used the exploit-created in-memory shell to try to deploy Cerber ransomware. Sophos said CryptoGuard blocked both ransomware attempts before damage occurred and found no evidence of data exfiltration or lateral movement in those cases.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 19 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
8 references tracked. Mallory keeps watching after this page renders.
cve.mitre.org
Open sourcenews.sophos.com
Open sourcecve.mitre.org
Open sourceblog.barracuda.com
Open sourcembsd.jp
Open sourcembsd.jp
Open sourceconfluence.atlassian.com
Open sourcevolexity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.