Website Security & Threat Management
Cloudflare observations of Confluence zero day (CVE-2022-26134)

Cloudflare observations of Confluence zero day (CVE-2022-26134)

6/5/2022 · Vaibhav Singhal, Himanshu Anand, Daniel Stinson-Diess, Sourov Zaman, Michael Tremante

What this post added

This post details Cloudflare's rapid response to the Confluence zero-day vulnerability (CVE-2022-26134). It covers the immediate engagement of WAF teams to deploy mitigation rules, the analysis of exploit attempts observed in the wild (including early detection prior to the official advisory), and the refinement of WAF rules to improve accuracy and reduce false positives. The post also outlines Cloudflare's internal security measures, including the use of Cloudflare Access to protect internal Confluence instances, and provides guidance for on-premise Confluence users on patching, enabling Cloudflare Access, and checking logs for indicators of compromise.

Read the original post ↗