← Back to CVE intelligence
CVE intelligenceCISA KEVRansomware use

CVE-2022-26134

Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability

Published Jun 3, 2022Sources checked Sep 12, 2026
9.8CRITICALCVSS out of 10
What this means

Actively exploited

CISA lists CVE-2022-26134 in its Known Exploited Vulnerabilities catalog, which means exploitation has been observed. The entry applies to Atlassian Confluence Server/Data Center.

  • Immediately block all internet traffic to and from affected products AND apply the update per vendor instructions [https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html] OR remove the affected products by the due date on the right. Note: Once the update is successfully deployed, agencies can reassess the internet blocking rules.
CISA KEVListedObserved exploitation
EPSS100.0%Estimated 30-day exploitation probability
Ransomware useReported by CISACISA KEV ransomware field
Threat actors2Source-linked actor relationships
Overview

What is CVE-2022-26134?

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.