"Critical Security Alert: Patch Atlassian Confluence Now, Warns CISA and FBI"

CISA, FBI, and MS-ISAC have issued a warning to network administrators to immediately patch their Atlassian Confluence servers against a critical privilege escalation flaw (CVE-2023-22515) that is actively being exploited in attacks. The flaw affects Confluence Data Center and Server 8.0.0 and later versions and can be remotely exploited without user interaction. Atlassian had previously advised customers to upgrade their instances or isolate them if upgrading was not possible. The organizations also encourage organizations to hunt for malicious activity and apply incident response recommendations. While exploitation has been limited so far, the ease of exploitation is expected to lead to widespread attacks on unpatched Confluence instances.
Reading Insights
0
12
1 min
vs 2 min read
72%
377 → 106 words
Want the full story? Read the original article
Read on BleepingComputer