Atlassian Confluence Flaw Exploited to Install Cryptominers

September 7, 2021

Security companies have reported that threat actors and researchers have actively scanned and exploited the Atlassian Confluence vulnerability.

The news comes just days after researchers publicly released a technical write-up on the vulnerability.

The Confluence Remote Code Execution vulnerability, known as CVE-2021-26084, allows an unauthenticated attacker to remotely execute commands on a vulnerable server.

While the cybersecurity intelligence company Bad Packets had used threat actors from different countries to download and execute PowerShell or Linux shell scripts, the investigation shows that the attacks are mainly to mine cryptocurrencies.

There are some additional concerns that the exploit could also be used for advanced attacks, including spreading the efforts through a network ransomware attack and data exfiltration.

Organizations running a Confluence Server are advised to install the latest updates as soon as possible.

For more information, read the original story in Bleeping Computer.

Top Stories

Related Articles

February 12, 2026 The Sun’s radiation has become an existential risk for spacecraft, and SpaceX is taking the fight underground, more...

February 12, 2026 Canadians will finally gain legal control over their financial data in 2026 as the federal government confirms more...

February 11, 2026 Workday’s CEO Carl Eschenbach is stepping down, less than a week after the enterprise software firm announced more...

February 11, 2026 In a sharp reversal that erased all gains made since Donald Trump’s 2025 election win, Bitcoin tumbled more...

Picture of TND News Desk

TND News Desk

Staff writer for Tech Newsday.
Picture of TND News Desk

TND News Desk

Staff writer for Tech Newsday.

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn