Exploited Known exploited (KEV) Ransomware use CVE-2022-26134

Cut the traffic before you fix it — an instruction that set the order on Confluence

Atlassian Confluence Server/Data Center Added to KEV Jun 2, 2022 Federal remediation due 2022-06-06

For the remote code execution flaw in Atlassian Confluence Server and Data Center, CISA required agencies to block all internet traffic to and from affected products immediately and then apply the update. The due date fell four days after listing.

Key facts

  • CVE IDCVE-2022-26134
  • Affected (vendor / product)Atlassian Confluence Server/Data Center
  • CWECWE-917
  • ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
  • Remediation due2022-06-06 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • CVE-2022-26134 is a remote code execution flaw in Atlassian Confluence Server and Data Center, reachable by someone who has not authenticated.
  • The required action is to cut every internet connection running into or out of the affected products at once, then put the update on as the vendor directs.
  • Removing the affected products altogether by the due date is offered as the alternative.
  • Once the update has been deployed successfully, agencies may reassess the internet blocking rules.
  • Listed 2 June 2022 with a due date of 6 June, a window of four days; among the 1,579 entries without an article this site holds as of 2026-09-05, 21 days is the most common at 1,002.

1An instruction with an order in it

The instruction in the previous article limited what counted as remediation. This one adds a sequence. Block the internet traffic first, then apply the update. Either alone will not do.

2Three stages

  1. 1ImmediatelyBlock all internet traffic to and from the affected products
  2. 2ThenApply the update per vendor instructions, or remove the products altogether by the due date
  3. 3The due date6 June 2022, four days after the entry appeared on 2 June 2022
  4. 4Once the update is deployedAgencies may reassess the internet blocking rules

The block is not meant to be permanent. The instruction itself says it may be revisited once the update has gone in successfully. The block is positioned as a way of buying time safely until the update lands.

3Four days

Of the 1,695 records this site holds as of 2026-09-05, those without an article1,579A window of 21 days is the most common, on 1,002 entries
Of those, entries given three days40Eight are given one or two days, seventeen are given seven
The window hereFour daysListed 2 June 2022, due 6 June 2022

Across the windows given for remediation, 21 days dominates at 1,002 entries, followed by 181 to 184 days at 255 and 14 days at 238. Single-digit windows are the exception: forty at three days, seventeen at seven, eight at one or two. Four days belongs on that exceptional side.

4The short window and the order go together

Applying an update everywhere within four days can be beyond a large organization. That is precisely why the block comes first. Even where the update cannot land in time, cutting the traffic closes the path. Setting an order is what makes a short deadline workable.

The next article takes up an entry where there was as yet nothing to apply.

Why it matters

A remediation instruction can carry not only what to do but the order in which to do it. Blocking traffic first and updating second reads as a design for making a short deadline workable, since the path can be closed even when the update cannot land in time. That the block is expressly revisitable once the update succeeds confirms how it is meant to function.

FAQ

Why require both blocking and updating?
The catalog gives no reason, but with a window of only four days, cutting the traffic closes the path even where the update cannot land in time.
How long does the block last?
The entry notes that once the update has been deployed successfully, agencies may reassess the internet blocking rules.
Is four days short?
Among the 1,579 entries without an article this site holds as of 2026-09-05, 21 days is the most common at 1,002, and single-digit windows are exceptional.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Vulnerabilities#KEV#CISA#United States#Cybersecurity
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.