Bottom line: Atlassian has addressed critical vulnerabilities in Confluence and Bitbucket to prevent exploitation by threat actors.
What's happening: Atlassian patched vulnerabilities in Confluence (CVE-2022-26132) and Bitbucket (CVE-2022-26133), which could be exploited to execute arbitrary code, access sensitive information, and elevate privileges. The vulnerabilities were identified in the Confluence and Bitbucket products.
What to do: Security leaders should prioritize applying these patches and monitor their environments for suspicious activity to protect sensitive data.