
6/3/2022 · Reid Tatoris, Daniel Stinson-Diess, Sourov Zaman, Vaibhav Singhal
What this post added
This post details the emergency response to CVE-2022-26134, a critical RCE vulnerability in Atlassian Confluence. Cloudflare engineers analyzed the vulnerability, prepared a WAF mitigation rule, and deployed it within hours of Atlassian's advisory. The rule (IDs 100531 and 408cff2b) was deployed at 23:38 UTC on June 2, 2022, with a default BLOCK action, protecting all WAF customers, including free tier users, running self-hosted Confluence. Additionally, Cloudflare Access provided protection by verifying authenticated users before requests reached the Confluence server.