Confluence Server reached end of life on February 15, 2024 — and three actively-exploited, CISA-KEV-listed CVEs (CVE-2021-26084, CVE-2022-26134, CVE-2023-22518) were each fixed only on then-supported branches. Every end-of-life Confluence branch still running carries at least one of them permanently; a 6.x server carries all three. All three are flagged by CISA for known ransomware campaign use. The full wave-by-wave record, version dates, and the honest way out.
The scoreboard: three waves, one pattern
| Wave | CVE | What it is | Severity | KEV added | Fixed only on | Left permanently vulnerable |
|---|---|---|---|---|---|---|
| 2021 | CVE-2021-26084 | Unauthenticated OGNL injection → RCE | 9.8 (NVD) | Nov 3, 2021 | 6.13, 7.4, 7.11, 7.12, 7.13 branches | 6.0–6.12 (4.x/5.x also named affected) |
| 2022 | CVE-2022-26134 | Unauthenticated OGNL injection → RCE | 9.8 (NVD) | Jun 2, 2022 | 7.4 and 7.13–7.18 branches | 6.x (every release after 1.3.0 affected) |
| 2023 | CVE-2023-22518 | Improper authorization → instance reset, attacker-created admin account | 9.8 (NVD); 10.0 (Atlassian, revised) | Nov 7, 2023 | 7.19.16, 8.3.4, 8.4.4, 8.5.3, 8.6.1 | 7.0–7.18 (non-LTS), 6.x, 5.x |
What's covered
- Wave one, 2021: CVE-2021-26084 — and everything before 6.13 is left behind
- Wave two, 2022: CVE-2022-26134 — same flaw class, same triage, new casualties
- Wave three, 2023: CVE-2023-22518 — the ransomware wave
- The scoreboard: three waves, one pattern
- Why this keeps happening: the lifecycle math
- What to actually do
Full guide with every version, risk scores, and live updates: https://endoflife.ai/article-confluence-cve-exposure
Top comments (0)