Confluence – Critical unauthenticated remote code execution vulnerability
confluence.atlassian.com
confluence.atlassian.com
This looks like a bad one, folks. Their advice is "turn off your confluence server until a patch is available".
Doesn't look like they got ours before I got to it, thankfully.