Attackers rapidly began exploiting CVE-2023-22527, a critical CVSS 10.0 remote code execution flaw in Atlassian Confluence Data Center and Confluence Server, within days of public disclosure. The vulnerability affects outdated Confluence 8 releases issued before December 5, 2023, as well as version 8.4.5, and stems from OGNL expression injection that can let unauthenticated attackers execute arbitrary code on exposed servers.
Telemetry from Shadowserver Foundation and The DFIR Report recorded nearly 40,000 exploitation attempts over three days from more than 600 unique IP addresses, indicating broad opportunistic scanning across the internet. Observed activity included callback testing and basic reconnaissance such as running whoami, suggesting attackers were validating access for potential follow-on compromise; at the time, more than 11,000 Atlassian instances were internet-accessible, underscoring the exposure risk for unpatched organizations.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
As of January 21, 2024, more than 11,000 Atlassian instances were accessible over the internet. The number of those instances actually vulnerable to CVE-2023-22527 was not known.
Attackers began actively exploiting CVE-2023-22527 within three days of its public disclosure. Shadowserver Foundation and The DFIR Report observed exploitation attempts starting as early as January 19, 2024.
ProjectDiscovery researchers Rahul Maini and Harsh Jaiswal published a technical analysis explaining that CVE-2023-22527 allows unauthenticated OGNL expression injection in Confluence. Their write-up described how the issue can be used to execute arbitrary code and system commands on affected systems.
Researchers recorded nearly 40,000 attempts to exploit CVE-2023-22527 from more than 600 unique IP addresses. The activity mainly involved callback testing and running the command 'whoami,' suggesting broad opportunistic scanning for vulnerable servers.
CVE-2023-22527 was publicly disclosed as a critical unauthenticated remote code execution flaw affecting Atlassian Confluence Data Center and Server, including 8.x releases issued before December 5, 2023 and version 8.4.5. The flaw enables OGNL expression injection that can lead to arbitrary code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.