
6/5/2022 · Vaibhav Singhal, Himanshu Anand, Daniel Stinson-Diess, Sourov Zaman, Michael Tremante
What this post added
This post details Cloudflare's rapid response to the Confluence zero-day vulnerability (CVE-2022-26134). It covers the immediate engagement of WAF teams to deploy mitigation rules, the analysis of exploit attempts observed in the wild (including early detection prior to the official advisory), and the refinement of WAF rules to improve accuracy and reduce false positives. The post also outlines Cloudflare's internal security measures, including the use of Cloudflare Access to protect internal Confluence instances, and provides guidance for on-premise Confluence users on patching, enabling Cloudflare Access, and checking logs for indicators of compromise.