In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are before version 6.13.23, from version 6.14.0 before 7.4.11, from version 7.5.0 before 7.11.6, and from version 7.12.0 before 7.12.5.
Published: 2021-09-07
Recently disclosed critical flaw in Atlassian Confluence Server is being exploited in the wild by attackers. Organizations should apply patches immediately. Background On August 25, Atlassian published a security advisory for a critical vulnerability in its Confluence Server and Data Center software.
https://www.infosecurity-magazine.com/news/amazon-russian-gru-hackers-target/
https://thehackernews.com/2025/12/amazon-exposes-years-long-gru-cyber.html
https://cyberscoop.com/amazon-threat-intel-russia-attacks-energy-sector-sandworm-apt44/
https://www.theregister.com/2025/12/15/amazon_ongoing_gru_campaign/
https://www.edgescan.com/wp-content/uploads/2024/03/2023-Vulnerability-Statistics-Report.pdf
https://securelist.com/exploits-and-vulnerabilities-q3-2024/114839/
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-317a
https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-190a
https://www.greynoise.io/blog/spike-in-atlassian-exploitation-attempts-patching-is-crucial
https://www.imperva.com/blog/imperva-detects-undocumented-8220-gang-activities/?web_view=true
https://www.tenable.com/cyber-exposure/a-look-inside-the-ransomware-ecosystem
https://www.tenable.com/cyber-exposure/2021-threat-landscape-retrospective
https://therecord.media/confluence-and-gitlab-servers-targeted-by-new-ransomware-strain
https://www.tenable.com/blog/aa23-215a-2022s-top-routinely-exploited-vulnerabilities
https://github.com/chengbochuan3/CVE-Confluence
https://github.com/Ahmed-Arafat-Mostafa/CyberGuard-Vulnerability-Scanner
https://github.com/karim852/KUMO-Domain-Recon-Tool
https://github.com/hermestoola/bb-hunter-pro
https://github.com/chiranths09/Syntecxhub_Project_Vulnerability-CVE-Scanner
https://github.com/odaysec/confluPwn
https://github.com/BBD-YZZ/Confluence-RCE
https://github.com/Lotus6/ConfluenceMemshell
https://github.com/Loginsoft-Research/Linux-Exploit-Detection
https://github.com/demining/Log4j-Vulnerability
https://github.com/34zY/APT-Backpack
https://github.com/quesodipesto/conflucheck
https://github.com/lleavesl/CVE-2021-26084
https://github.com/TheclaMcentire/CVE-2021-26084_Confluence
https://github.com/thomsdev/CVE-2021-26084
https://github.com/rakhanobe/CVE-2021-26084
https://github.com/orangmuda/CVE-2021-26084
https://github.com/onsecuredev/CVE-2021-26084
https://github.com/byteofjoshua/CVE-2021-26084
https://github.com/byteofandri/CVE-2021-26084
https://github.com/ludy-dev/CVE-2021-26084_PoC
https://github.com/nizarbamida/CVE-2021-26084-patch-
https://github.com/toowoxx/docker-confluence-patched
https://github.com/1ZRR4H/CVE-2021-26084
https://github.com/march0s1as/CVE-2021-26084
https://github.com/Loneyers/CVE-2021-26084
https://github.com/p0nymc1/CVE-2021-26084
https://github.com/Osyanina/westone-CVE-2021-26084-scanner
https://github.com/0xf4n9x/CVE-2021-26084
https://github.com/prettyrecon/CVE-2021-26084_Confluence
https://github.com/r0ckysec/CVE-2021-26084_Confluence
https://github.com/JKme/CVE-2021-26084
https://github.com/crowsec-edtech/CVE-2021-26084
https://github.com/carlosevieira/CVE-2021-26084
https://github.com/Sma11New/PocList
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-26084
https://jira.atlassian.com/browse/CONFSERVER-67940
http://packetstormsecurity.com/files/167449/Atlassian-Confluence-Namespace-OGNL-Injection.html
Published: 2021-08-30
Updated: 2026-06-17
Named Vulnerability: ConfluenzaKnown Exploited Vulnerability (KEV)
Base Score: 7.5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
Severity: High
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
EPSS: 0.99999