Product of Atlassian

Confluence Data Center and Server

As of , 3 Atlassian Confluence Data Center and Server vulnerabilities are on CISA's list of exploited vulnerabilities, 3 of them used in ransomware campaigns; 0 were added in 2026. Patch first: CVE-2023-22527.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2023-22527Template InjectionAtlassian Confluence Data Center and ServerPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
2CVE-2023-22518Improper AuthorizationAtlassian Confluence Data Center and ServerPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
3CVE-2023-22515Broken Access ControlAtlassian Confluence Data Center and ServerPatch this weekRansomware use; Metasploit module; EPSS 0.990.99

Added each year

0.511.522023: 2220232024: 1120242025: nonenone20252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20232
20241
2025none
2026none

Used in ransomware