CVE-2021-26072
52Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 39%
from disclosure to weapon
Published on NVDApr 1
VulnCheck+1679d
exploitation probability
39%top 2% of all CVEs
observed exploitation
yesVulnCheck
The WidgetConnector plugin in Confluence Server and Confluence Data Center before version 5.8.6 allowed remote attackers to manipulate the content of internal network resources via a blind Server-Side Request Forgery (SSRF) vulnerability.