CVE-2026-21580
Confluence Data Center and Server Vulnerabilities Allow Stored XSS Privilege Escalation and Security Misconfiguration
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A critical vulnerability in Confluence Data Center and Server allows unauthenticated attackers to execute malicious code and gain elevated privileges by exploiting security misconfigurations. This could lead to unauthorized system access and the compromise of user sessions. It is important to confirm if your deployment