Proof-of-concept exploits for the critical vulnerability CVE-2022-26134, which affects Atlassian Confluence servers and Data Center , have now been publicly released. Therefore, the need to install the update is high.
See also: Atlassian Confluence zero-day: Actively used in attacks

This is a critical vulnerability , which does not require authentication, and affects all Atlassian Confluence and Data Center 2016 servers after version 1.3.0.
Successful exploitation allows unauthenticated, remote attackers to create new administrator accounts, execute commands, and ultimately take over the server.
The vulnerability was disclosed last week after Volexity discovered it was being used by multiple threat actors in attacks. However, no patch had yet been released, and Atlassian advised administrators to take the servers offline or block them from the internet.
On Friday, Atlassian released security updates to fix the vulnerability due to the increase in attacks.
See also: Steam Deck: Software update reduces fan noise
A proof-of-concept exploit for the Atlassian Confluence vulnerability was publicly released on Friday afternoon. The exploit quickly spread widely across the internet over the weekend, with researchers sharing it on Twitter highlighting how easy it is to exploit.

Andrew Morris, CEO of cybersecurity firm GreyNoise, tweeted that they had started seeing 23 unique IP addresses exploiting Atlassian vulnerabilities.
Today, GreyNoise reports that the number of unique IP addresses attempting to exploit this vulnerability has increased nearly tenfold, to 211 unique IP addresses.
Confluence exploits published online show how to create new administrator accounts, force DNS requests, collect information, and create reverse shells.
If you have not yet patched the security vulnerability on your Confluence or Data Center servers, you should do so immediately before you become a victim of an attack.
See also: Update for VMware authentication bypass bug
“The released versions 7.4.17, 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4 and 7.18.1 contain a fix for this issue,” Atlassian explains.
If for some reason you are unable to patch servers , Atlassian is providing mitigations for Confluence 7.0.0 through version 7.18.0.
As Confluence servers are an attractive target for initial access to a corporate network, devices should be updated immediately or mitigation measures taken.
Source: BleepingComputer
