When the vulnerability was announced last week, we powered off our server until the patch was made available, and then applied it. We are running Confluence Server 7.13.7 LTS.
Earlier today, Sophos Antivirus for Linux (running on our Confluence Server) detected a virus:
Path: /var/atlassian/application-data/confluence/temp/upload_fd4c861b_e75a_4310_ae4e_5b10c650bebc_00000009.tmp
What was detected: Troj/WebShel-CS
We require 2FA authentication to login to Confluence, so I'm not sure how this was uploaded, unless some vulnerability still exists?