tag
Atlassian
CVE-2023-22527
web
CRITICAL 10
KEV
Ransomware
EPSS 100%
Confluence SSTI RCE - CVE-2023-22527
CVE-2023-22527 is a CVSS 10.0 unauthenticated Remote Code Execution vulnerability in Atlassian Confluence Data Center and Server. The vulnerability is a Server-Side Template Injection (SSTI) in the Velocity/Freemarker template engine, reachable via the…
Patched
2026-05-17