CVE-2022-26134

Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 17 articles

EPSS Score

Source: FIRST.org · 2026-05-24
94.41%
probability
This CVE has a 94.41% probability of being exploited in the next 30 days.
0% Top 100.0th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Description

Project Zero
Unauthenticated Remote Code Execution

Google Project Zero

Discovered
May 31, 2022
Patched
June 3, 2022
Reported by
Volexity
Root Cause Analysis
???

Exploits & PoC

W01fh4cker/Serein

【懒人神器】一款图形化、批量采集url、批量对采集的url进行各种nday检测的工具。可用于src挖掘、cnvd挖掘、0day利用、打造自己的武器库等场景。可以批量利用Actively Exploited Atlassian Confluence 0Day CVE-2022-26134和DedeCM

1245
jbaines-r7/through_the_wire

CVE-2022-26134 Proof of Concept

171
hev0x/CVE-2022-26134

Confluence Pre-Auth Remote Code Execution via OGNL Injection (CVE-2022-26134)

44
crowsec-edtech/CVE-2022-26134

CVE-2022-26134 - Confluence Pre-Auth RCE | OGNL injection

31
nxtexploit/CVE-2022-26134

Atlassian Confluence (CVE-2022-26134) - Unauthenticated Remote code execution (RCE)

29
SNCKER/CVE-2022-26134

[CVE-2022-26134]Confluence OGNL expression injected RCE with sandbox bypass.

28
SIFalcon/confluencePot

Simple Honeypot for Atlassian Confluence (CVE-2022-26134)

20
AmoloHT/CVE-2022-26134

「💥」CVE-2022-26134 - Confluence Pre-Auth RCE

14
whokilleddb/CVE-2022-26134-Confluence-RCE

Exploit for CVE-2022-26134: Confluence Pre-Auth Remote Code Execution via OGNL Injection

13
9 repos — triés par ⭐ Rechercher sur GitHub ↗
Security Advisory 2022-040
CERT-EU Jun 03, 2022

Signal Intelligence

Confidence
92%
EPSS 94.41%
Mentions 17
Last Seen May 27, 2026

CNA Information

Analyst Note

CVE-2022-26134 is a critical unauthenticated OGNL injection vulnerability in Confluence with CVSS 9.8, confirmed by CERT-EU security advisory and referenced in threat intelligence reporting on active exploitation by Chinese threat actors. The presence in Google Project Zero and documented real-world targeting provides strong corroboration for the confirmed status.

Threat Actors 43

APT 41
apt_group Information theft and espionage 🇨🇳 CN
Turla Group
apt_group Information theft and espionage Russian Federation
Cobalt
apt_group Financial crime 🇷🇺 RU
APT 28
apt_group Information theft and espionage 🇷🇺 RU
SaintBear
apt_group Information theft and espionage 🇷🇺 RU
CHRYSENE
apt_group Information theft and espionage 🇮🇷 IR
Vicious Panda
apt_group Information theft and espionage 🇨🇳 CN
Harvester
apt_group Information theft and espionage Unknown
BelialDemon
apt_group 🇷🇺 RU
Hacking Team
apt_group 🇮🇹 IT
SCATTERED SPIDER
apt_group Financial crime 🇺🇸 US
MAGNALLIUM
apt_group Sabotage and destruction 🇮🇷 IR
Ice Fog
apt_group Information theft and espionage 🇨🇳 CN
DNSpionage
apt_group Information theft and espionage 🇮🇷 IR
Kinsing
apt_group 🇷🇺 RU
Infy
apt_group Information theft and espionage 🇮🇷 IR
Evilnum
apt_group Information theft and espionage
TeamTNT
apt_group 🇩🇪 DE
GhostR
apt_group 🇨🇳 CN
Pirate Panda
apt_group Information theft and espionage 🇨🇳 CN
[Unnamed group]
apt_group 🇨🇳 CN
FamousSparrow
apt_group Information theft and espionage 🇨🇳 CN
FIN8
apt_group Financial crime 🇷🇺 RU
Earth Estries
apt_group Information theft and espionage 🇨🇳 CN
Returned Libra
apt_group 🇨🇳 CN
APT 22
apt_group Information theft and espionage 🇨🇳 CN
Rocke
apt_group 🇨🇳 CN
Moonstone Sleet
apt_group 🇰🇷 KR
APT 6
apt_group Information theft and espionage 🇨🇳 CN
Earth Longzhi
apt_group 🇨🇳 CN
Hezb
apt_group Information theft and espionage 🇱🇧 LB
The White Company
apt_group Information theft and espionage 🇨🇳 CN
Test Panda
apt_group 🇨🇳 CN
Shadow Network
apt_group Information theft and espionage 🇨🇳 CN
Mana Team
apt_group 🇨🇳 CN
Poisonous Panda
apt_group Information theft and espionage 🇨🇳 CN
Operation Shadow Force
apt_group 🇨🇳 CN
DEV-0586
apt_group Sabotage and destruction 🇷🇺 RU
APT 5
apt_group Information theft and espionage 🇨🇳 CN
Beijing Group
apt_group Information theft and espionage 🇨🇳 CN
PlushDaemon
apt_group Information theft and espionage 🇨🇳 CN
Operation Black Atlas
apt_group Financial crime
Dark Partners
apt_group

Triage Info

Decided atMar 03, 2026