US Cybersecurity Agency urges users to patch Confluence
On Friday the US Cybersecurity Agency tweeted an alert urging Confluence Server admins to patch and upgrade Confluence to the latest version.
The tweet mentioned not to wait until after the weekend as attackers are actively exploiting a code execution vulnerability discovered in a prior version.
This is the tweet: 👉[https://twitter.com/CNMF_CyberAlert/status/1433787671785185283?s=20]
The critical issue found in Confluence versions listed on the ticket was made public on the 25th of August, advising users to patch as soon as possible.
This vulnerability enables attackers to execute code remotely without authenticating. If you're on Confluence Server, ask your admin to check the version you're on and patch ASAP if on any of the affected versions.