CVE-2022-26138
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 20, 2026
5 articles
EPSS Score
Source: FIRST.org · 2026-05-24
94.32%
probability
This CVE has a 94.32% probability
of being exploited in the next 30 days.
0%
Top 100.0th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Attack Intelligence
CWE-1390
· Weak Authentication
CWE-1391
CWE-284
· Improper Access Control
CWE-287
· Improper Authentication
CWE-330
· Use of Insufficiently Random Values
CWE-344
CWE-657
CWE-671
CWE-693
· Protection Mechanism Failure
CWE-710
· Improper Adherence to Coding Standards
CWE-798
· Use of Hard-coded Credentials
Exploits & PoC
z92g/CVE-2022-26138
Confluence Hardcoded Password POC
15
shavchen/CVE-2022-26138
PoC CVE-2022-26138 — shavchen/CVE-2022-26138
0
2 repos — triés par ⭐
Rechercher sur GitHub ↗
Atlassian patches critical Confluence zero-day exploited in attacks
BleepingComputer
Oct 04, 2023
Introducing Qualys Threat Research Thursdays
Qualys
Sep 01, 2022
Signal Intelligence
Confidence
92%
EPSS
94.32%
Mentions
5
Last Seen
Oct 04, 2023
CNA Information
Analyst Note
CVE-2022-26138 is explicitly named as a zero-day in BleepingComputer's headline ('Atlassian patches critical Confluence zero-day exploited in attacks') and TheHackerNews reports active exploitation occurring within a week after Atlassian's patch release. CISA's addition to the Known Exploited Vulnerabilities Catalog provides independent confirmation of active wild exploitation.
Threat Actors 5
Turla Group
apt_group
Information theft and espionage
Russian Federation
APT 29
apt_group
Information theft and espionage
🇷🇺 RU
APT32
apt_group
Information theft and espionage
🇻🇳 VN
SaintBear
apt_group
Information theft and espionage
🇷🇺 RU
DEV-0586
apt_group
Sabotage and destruction
🇷🇺 RU
Triage Info
Decided atMar 20, 2026