Atlassian has advised all Confluence Data Center and Server customers to patch a critical vulnerability identified as an improper authorization bug (CVE-2023-22518) that could lead to significant data loss if exploited by an attacker. There have been no reports of active exploitation so far, and the bug doesn’t impact data confidentiality. The company has already released new versions of Confluence Data Center and Server to address the defect.

Exposed credentials are giving attackers a head start many organizations don’t see
Compromised credentials can remain active long after passwords are created, leaving organizations trying to identify exposed accounts before attackers can use them. The 2026 Credential


