Atlassian Confluence is under heavy attack

An abstract image of padlocks overlaying a digital background.
(Image credit: Shutterstock)

Cybersecurity researchers at the US Cyber Command (USCYBERCOM) have urged admins to immediately patch their on-premise Atlassian Confluence collaboration platform, which is at the receiving end of an ongoing attack.

USCYBERCOM put out a public notice on Twitter informing Atlassian users of an active large-scale exploitation campaign that it expects to accelerate. 

“Please patch immediately if you haven’t already—this cannot wait until after the weekend,” USCYBERCOM wrote on Twitter

The flaw, tracked as CVE-2021-26084, enables threat actors to remotely execute arbitrary code on the popular workplace collaboration platform.

Ongoing campaign

Described as “an OGNL injection vulnerability,” the bug exists in the Atlassian Confluence Server and Confluence Data Center products, both of which are vulnerable to unauthenticated remote attackers.

With a high CVSS severity rating of 9.8 out of 10, the vulnerability was first reported on July 27, 2021. However, given its serious nature, Atlassian didn’t publish details about its exploitation mechanism, even after it had issued a patch last month on August 25, 2021.

Reportedly however, threat actors began exploiting the vulnerability soon after the patch was released. Threat intelligence firm Bad Packets first detected “mass scanning and exploit activity” against the vulnerability from hosts in Brazil, China, Hong Kong, Nepal, Romania, Russia and the US, before Atlassian updated its advisory warning users about the attack.

“This vulnerability is being actively exploited in the wild. Affected servers should be patched immediately,” said Atlassian.

The vulnerability affects Confluence Server and Data Center versions before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
Best free Linux firewalls
Fortinet warns a critical vulnerability in its systems could let attackers breach company networks
A person at a laptop with a cybersecure lock symbol floating above it.
Hackers are still using old Ivanti bugs to break into networks
A digital representation of a lock
A critical security flaw in Apache Struts is under attack, so patch now
Flag of the People's Republic of China overlaid with a technological network of wires and circuits.
One of the biggest flaws exploited by Salt Typhoon hackers has had a patch available for years
The best free firewall
Palo Alto warns another major firewall hack has been detected
Cyber-security
Adobe releases software updates to patch security issues
Latest in Security
China
Chinese hackers targeting Juniper Networks routers, so patch now
Google Chrome dark mode
Google updates Chrome extension rules to ban affiliate link injection without user action or benefit
Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard
This worrying botnet targets unsecure TP-Link routers - thousands of devices already hacked
Avast cybersecurity
UK cybersecurity sector could be worth £13bn, research shows
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
Trump
Hackers are abusing $TRUMP tokens to lure victims in to new phishing scam
Latest in News
Lilo & Stitch Official Trailer
Stitch crashes into earth and steals our hearts with the first trailer for the live-action Lilo & Stitch
GTA 5
GTA Online publisher Take-Two is gunning for a black market that’s basically heaven for cheaters
Y2K cast looking shocked
Y2K has a streaming release date on Max, so you can witness the technology uprising at home
The Discovery+ homepage
Discovery+ just got a big update to its streaming app that makes it more like Max – here are 5 great new features to try
Two Android phones on a green and blue background showing Google Messages
Struggling with slow Google Messages photo transfers? Google says new update will make 'noticeable difference'
China
Chinese hackers targeting Juniper Networks routers, so patch now