Known exploited / historically exploited security risk
CVE-2022-26134 — Confluence Server and Data Center
A remotely exploitable vulnerability affecting Atlassian Confluence Server and Data Center. It was included among routinely exploited vulnerabilities and in CISA's Known Exploited Vulnerabilities program.
Business relevance
If Confluence Server and Data Center is present in your environment, confirm whether the installed version and configuration are affected. The existence of this CVE does not by itself prove that a specific system is vulnerable or compromised.
What to check
- Identify Confluence Server or Data Center instances.
- Confirm the installed Confluence version.
- Determine whether the service is internet-facing.
- Apply Atlassian-supported remediation and review exposure.
Source record
Authoritative source: CISA routinely exploited vulnerabilities advisory and Known Exploited Vulnerabilities program.
CompFlorida record reviewed: September 21, 2026.
Vendor: Atlassian
Product: Confluence Server and Data Center
CVE: CVE-2022-26134
Need help checking applicability?
CompFlorida can help identify the product/version in use, review exposure and coordinate the appropriate remediation path.
Request a Technology Risk Review
