CVE-2022-26134
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 3, 2026
17 articles
EPSS Score
Source: FIRST.org · 2026-05-24
94.41%
probability
This CVE has a 94.41% probability
of being exploited in the next 30 days.
0%
Top 100.0th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Description
Project ZeroUnauthenticated Remote Code Execution
Attack Intelligence
Google Project Zero
Discovered
May 31, 2022
Patched
June 3, 2022
Reported by
Volexity
Root Cause Analysis
???
Exploits & PoC
W01fh4cker/Serein
【懒人神器】一款图形化、批量采集url、批量对采集的url进行各种nday检测的工具。可用于src挖掘、cnvd挖掘、0day利用、打造自己的武器库等场景。可以批量利用Actively Exploited Atlassian Confluence 0Day CVE-2022-26134和DedeCM
1245
jbaines-r7/through_the_wire
CVE-2022-26134 Proof of Concept
171
hev0x/CVE-2022-26134
Confluence Pre-Auth Remote Code Execution via OGNL Injection (CVE-2022-26134)
44
crowsec-edtech/CVE-2022-26134
CVE-2022-26134 - Confluence Pre-Auth RCE | OGNL injection
31
nxtexploit/CVE-2022-26134
Atlassian Confluence (CVE-2022-26134) - Unauthenticated Remote code execution (RCE)
29
SNCKER/CVE-2022-26134
[CVE-2022-26134]Confluence OGNL expression injected RCE with sandbox bypass.
28
SIFalcon/confluencePot
Simple Honeypot for Atlassian Confluence (CVE-2022-26134)
20
AmoloHT/CVE-2022-26134
「💥」CVE-2022-26134 - Confluence Pre-Auth RCE
14
whokilleddb/CVE-2022-26134-Confluence-RCE
Exploit for CVE-2022-26134: Confluence Pre-Auth Remote Code Execution via OGNL Injection
13
9 repos — triés par ⭐
Rechercher sur GitHub ↗
Atlassian fixes Confluence zero-day widely exploited in attacks
BleepingComputer
Jun 03, 2022
Critical Atlassian Confluence zero-day actively used in attacks
BleepingComputer
Jun 02, 2022
Defense Lessons From the Black Basta Ransomware Playbook
Qualys
Feb 25, 2025
Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
Tenable-Research
May 27, 2026
NSA Alert: Topmost CVEs Actively Exploited By People’s Republic of China State-Sponsored Cyber Actors
Qualys
Oct 07, 2022
Security Advisory 2022-040
CERT-EU
Jun 03, 2022
From Log4j to IIS, China’s Hackers Turn Legacy Bugs into Global Espionage Tools
TheHackerNews
Nov 07, 2025
Microsoft June 2022 Patch Tuesday fixes 1 zero-day, 55 flaws
BleepingComputer
Jun 14, 2022
Microsoft Warns of Uptick in Hackers Leveraging Publicly-Disclosed 0-Day Vulnerabilities
TheHackerNews
Sophos Firewall zero-day bug exploited weeks before fix
BleepingComputer
Jun 16, 2022
Signal Intelligence
Confidence
92%
EPSS
94.41%
Mentions
17
Last Seen
May 27, 2026
CNA Information
Analyst Note
CVE-2022-26134 is a critical unauthenticated OGNL injection vulnerability in Confluence with CVSS 9.8, confirmed by CERT-EU security advisory and referenced in threat intelligence reporting on active exploitation by Chinese threat actors. The presence in Google Project Zero and documented real-world targeting provides strong corroboration for the confirmed status.
Threat Actors 43
APT 41
apt_group
Information theft and espionage
🇨🇳 CN
Turla Group
apt_group
Information theft and espionage
Russian Federation
Cobalt
apt_group
Financial crime
🇷🇺 RU
APT 28
apt_group
Information theft and espionage
🇷🇺 RU
SaintBear
apt_group
Information theft and espionage
🇷🇺 RU
CHRYSENE
apt_group
Information theft and espionage
🇮🇷 IR
Vicious Panda
apt_group
Information theft and espionage
🇨🇳 CN
Harvester
apt_group
Information theft and espionage
Unknown
BelialDemon
apt_group
🇷🇺 RU
Hacking Team
apt_group
🇮🇹 IT
SCATTERED SPIDER
apt_group
Financial crime
🇺🇸 US
MAGNALLIUM
apt_group
Sabotage and destruction
🇮🇷 IR
Ice Fog
apt_group
Information theft and espionage
🇨🇳 CN
DNSpionage
apt_group
Information theft and espionage
🇮🇷 IR
Kinsing
apt_group
🇷🇺 RU
Infy
apt_group
Information theft and espionage
🇮🇷 IR
Evilnum
apt_group
Information theft and espionage
TeamTNT
apt_group
🇩🇪 DE
GhostR
apt_group
🇨🇳 CN
Pirate Panda
apt_group
Information theft and espionage
🇨🇳 CN
[Unnamed group]
apt_group
🇨🇳 CN
FamousSparrow
apt_group
Information theft and espionage
🇨🇳 CN
FIN8
apt_group
Financial crime
🇷🇺 RU
Earth Estries
apt_group
Information theft and espionage
🇨🇳 CN
Returned Libra
apt_group
🇨🇳 CN
APT 22
apt_group
Information theft and espionage
🇨🇳 CN
Rocke
apt_group
🇨🇳 CN
Moonstone Sleet
apt_group
🇰🇷 KR
APT 6
apt_group
Information theft and espionage
🇨🇳 CN
Earth Longzhi
apt_group
🇨🇳 CN
Hezb
apt_group
Information theft and espionage
🇱🇧 LB
The White Company
apt_group
Information theft and espionage
🇨🇳 CN
Test Panda
apt_group
🇨🇳 CN
Shadow Network
apt_group
Information theft and espionage
🇨🇳 CN
Mana Team
apt_group
🇨🇳 CN
Poisonous Panda
apt_group
Information theft and espionage
🇨🇳 CN
Operation Shadow Force
apt_group
🇨🇳 CN
DEV-0586
apt_group
Sabotage and destruction
🇷🇺 RU
APT 5
apt_group
Information theft and espionage
🇨🇳 CN
Beijing Group
apt_group
Information theft and espionage
🇨🇳 CN
PlushDaemon
apt_group
Information theft and espionage
🇨🇳 CN
Operation Black Atlas
apt_group
Financial crime
Dark Partners
apt_group
Triage Info
Decided atMar 03, 2026