2022-06-03
Confluence Server and Data Center - CVE-2022-26134 - Critical severity unauthenticated remote code execution vulnerability https://confluence.atlassian.com/ ... There is no fix at the moment. So packet filtering, additional login or disabling it seems the best mitigation.
The Register
Atlassian warns users to restrict internet access to its Confluence software, or disable it, in light of an unpatched critical RCE flaw actively under attack
CISA's suggested action is to take the thing offline until it can be fixed, Atlassian has added a possible defence