Cybersecurity Alerts

Actively Exploited Vulnerabilities

← Back to Cybersecurity Alerts

CVE-2021-26084

Atlassian | Confluence Server and Data CenterAdded 2021-11-03Remediation Deadline 2021-11-17Active Ransomware Campaign

Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability

Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code.

Required Action

Apply updates per vendor instructions.

Weakness Classification

CWE-917

References