Cut the traffic before you fix it — an instruction that set the order on Confluence
For the remote code execution flaw in Atlassian Confluence Server and Data Center, CISA required agencies to block all internet traffic to and from affected products immediately and then apply the update. The due date fell four days after listing.
Key facts
- CVE IDCVE-2022-26134
- Affected (vendor / product)Atlassian Confluence Server/Data Center
- CWECWE-917
- ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
- Remediation due2022-06-06 (U.S. federal civilian agencies, BOD 22-01)
Key points
- CVE-2022-26134 is a remote code execution flaw in Atlassian Confluence Server and Data Center, reachable by someone who has not authenticated.
- The required action is to cut every internet connection running into or out of the affected products at once, then put the update on as the vendor directs.
- Removing the affected products altogether by the due date is offered as the alternative.
- Once the update has been deployed successfully, agencies may reassess the internet blocking rules.
- Listed 2 June 2022 with a due date of 6 June, a window of four days; among the 1,579 entries without an article this site holds as of 2026-09-05, 21 days is the most common at 1,002.
1An instruction with an order in it
The instruction in the previous article limited what counted as remediation. This one adds a sequence. Block the internet traffic first, then apply the update. Either alone will not do.
2Three stages
- 1ImmediatelyBlock all internet traffic to and from the affected products
- 2ThenApply the update per vendor instructions, or remove the products altogether by the due date
- 3The due date6 June 2022, four days after the entry appeared on 2 June 2022
- 4Once the update is deployedAgencies may reassess the internet blocking rules
The block is not meant to be permanent. The instruction itself says it may be revisited once the update has gone in successfully. The block is positioned as a way of buying time safely until the update lands.
3Four days
Across the windows given for remediation, 21 days dominates at 1,002 entries, followed by 181 to 184 days at 255 and 14 days at 238. Single-digit windows are the exception: forty at three days, seventeen at seven, eight at one or two. Four days belongs on that exceptional side.
4The short window and the order go together
Applying an update everywhere within four days can be beyond a large organization. That is precisely why the block comes first. Even where the update cannot land in time, cutting the traffic closes the path. Setting an order is what makes a short deadline workable.
The next article takes up an entry where there was as yet nothing to apply.
Why it matters
A remediation instruction can carry not only what to do but the order in which to do it. Blocking traffic first and updating second reads as a design for making a short deadline workable, since the path can be closed even when the update cannot land in time. That the block is expressly revisitable once the update succeeds confirms how it is meant to function.
FAQ
Why require both blocking and updating?
How long does the block last?
Is four days short?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).