Skip to content
COOEY

EXPOSURES › CVE-2021-26084

CVE-2021-26084

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-26084 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 95/100 ransomwarerceexploited-in-wild

An unauthenticated attacker could execute code on vulnerable Atlassian Confluence servers via OGNL injection, and this vulnerability is actively exploited in the wild, often linked to ransomware attacks.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
Widespread exploitation and CISA inclusion indicate a serious failure with significant fallout.
cvefeed.io ↗ severe-fallout -0.90
Explicitly flagged as actively exploited, a severe indicator.
"CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks."
cooey ↗ severe-fallout -0.80
Initial reporting focused on the vulnerability itself.
"Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code."
CISA ↗ severe-fallout -0.80
CISA's inclusion confirms active exploitation, a serious failure.
"CISA Adds Three Known Exploited Vulnerabilities to Catalog"
xposedornot.com ↗ severe-fallout -0.60
Mentioned in a list of breaches, no specific judgment.
"7-Eleven (2026, 281.3K records)"
www.cvefind.com ↗ severe-fallout -0.60
Neutral description of CVE data, no judgment.
"CVE, short for Common Vulnerabilities and Exposures, is a list of publicly disclosed computer security flaws."
app.opencve.io ↗ severe-fallout -0.50
Brief mention, no specific judgment.
"The Essential Addons for Elementor plugin is vulnerable to Stored Cross-Site Scripting..."
cybersecuritynews.com ↗ severe-fallout +0.00
Brief mention in a broader context of vulnerabilities, no specific judgment.
"Microsoft SharePoint Server flaws are being actively exploited to gain remote code execution..."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.