SophiaX
🔍
LIVE
· New victim: cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· New victim: 6,898 new IOCs ingested in last 24h cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· 6,898 new IOCs ingested in last 24h

CVE-2023-22518

⚡ CISA KEV🔐 Ransomware
Published: —Modified: —Vendor: AtlassianProduct: Confluence Data Center and Server
—
CVSS v3
100.0%
EPSS
⚡ Added to KEV on 2023-11-07 · Federal agencies must remediate by 2023-11-28
Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data.
💣 Public Exploits0
From Exploit-DB
No public exploits in Exploit-DB.
🔍 Sigma Detection Rules4
Rules tagged with this CVE
highCVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Linux)linux—
mediumCVE-2023-22518 Exploitation Attempt - Suspicious Confluence Child Process (Windows)windows—
mediumCVE-2023-22518 Exploitation Attempt - Vulnerable Endpoint Connection (Proxy)——
mediumCVE-2023-22518 Exploitation Attempt - Vulnerable Endpoint Connection (Webserver)——
🛠️ Patch Details2
Affected/fixed versions from threat intel reports
Atlassian Confluence Data Centeraffected versions12.1.4-h6source ↗
Atlassian Confluence Serveraffected versions12.1.4-h6source ↗
📎 References0
No reference URLs.