Skip to content
VulniPulse

Atlassian Security Advisories & CVEs

166 advisories tracked · Atlassian (security@atlassian.com CNA) via NVD · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Atlassian CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Atlassian device is affected

Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Atlassian's recent advisories.

Official source

Atlassian (security@atlassian.com CNA) via NVD

Atlassian is its own CVE Numbering Authority. VulniPulse ingests Atlassian's CVEs from the NVD CNA feed (security@atlassian.com), each linking to its security advisory / Jira ticket. Covers Confluence (Server & Data Center), Jira (Software & Service Management), Bitbucket, Bamboo, Crowd and Fisheye/Crucible — self-hosted Confluence/Jira are repeatedly hit by mass-exploited RCE and auth-bypass bugs (CVE-2023-22515, CVE-2022-26134), so a huge patch-now audience.

Latest Atlassian advisories

Critical9.3Atlassian

Critical [CVE-2026-21580] This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center and Server

This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center and Server. This Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability, with a CVSS Score of 8.6, allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser, perform actions as a higher-privileged user, and to get into the system utilizing loopholes exposed from security best-practices being overlooked. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center and Server 9.2: Upgrade to a release greater than or equal to 9.2.21 See the release notes ([ ]). This vulnerability was reported via our Bug Bounty program. Affected products named by the advisory: Confluence Server.

CVE-2026-21580
Confluence
Aug 18, 2026
High7.6Atlassian

High [CVE-2026-21584] Confluence: This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0 of Bamboo Data Center

This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, and 12.1.0 of Bamboo Data Center. This Improper Authorization vulnerability, with a CVSS Score of 7.6, allows an authenticated attacker to gain unintended access and can lead to the exposure of resources or functionality, possibly providing attackers with sensitive information or even execute arbitrary code. Atlassian recommends that Bamboo Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: - Bamboo Data Center 10.2: Upgrade to a release greater than or equal to 10.2.22 See the release notes ( ). This vulnerability was reported via our Penetration Testing program.

CVE-2026-21584
Bamboo / Crowd / Fisheye
Aug 18, 2026
High8.8Atlassian

High [CVE-2026-21582] Confluence: This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 of Crowd Data Center

This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in version 7.2.1 of Crowd Data Center. This BASM (Broken Authentication & Session Management) vulnerability, with a CVSS Score of 8.8, allows an unauthenticated attacker to perform actions as another user. Atlassian recommends that Crowd Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Crowd Data Center 7.2: Upgrade to a release greater than or equal to 7.2.2 See the release notes ( ). This vulnerability was reported via our Penetration Testing program.

CVE-2026-21582
Bamboo / Crowd / Fisheye
Aug 18, 2026
High8.0Atlassian

High [CVE-2026-21575] Atlassian: This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows

This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Sourcetree for Mac and Sourcetree for Windows customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: - Sourcetree for Mac and Sourcetree for Windows 3.4: Upgrade to a release greater than or equal to 3.4.13 See the release notes ( ). This vulnerability was reported via our Bug Bounty program.

CVE-2026-21575
Unclassified
Jul 21, 2026
High7.1Atlassian

High [CVE-2026-21577] This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center

This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a host connected to a network. Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.17 See the release notes ([ ]). This vulnerability was reported via our Penetration Testing program.

CVE-2026-21577
Confluence
Jul 21, 2026
High8.2Atlassian

High [CVE-2026-21579] This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center

This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This Information Disclosure vulnerability, with a CVSS Score of 8.2, allows an unauthenticated attacker to view sensitive information via an Information Disclosure vulnerability. Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.22 See the release notes ([ ]). This vulnerability was reported via our Atlassian (Internal) program.

CVE-2026-21579
Confluence
Jul 21, 2026
Critical9.4Atlassian

Critical [CVE-2026-21571] Confluence: This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center

This Critical severity OS Command Injection vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 9.4 and a CVSS Vector of CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H allows an authenticated attacker to execute commands on the remote system, which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires no user interaction. your instance to one of the specified supported fixed versions: See the release notes ([ ]). Affected products named by the advisory: Confluence; Atlassian.

CVE-2026-21571
ConfluenceBamboo / Crowd / Fisheye
Apr 21, 2026
High8.6Atlassian

High [CVE-2026-21570] Confluence: This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0…

This High severity RCE (Remote Code Execution) vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.6, allows an authenticated attacker to execute malicious code on the remote system. Atlassian recommends that Bamboo Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Bamboo Data Center 9.6: Upgrade to a release greater than or equal to 9.6.24 Bamboo Data Center 10.2: Upgrade to a release greater than or equal to 10.2.16 Bamboo Data Center 12.1: Upgrade to a release greater than or equal to 12.1.3 See the release notes ([ ]). This vulnerability was reported via our Atlassian (Internal) program. Affected products named by the advisory: Confluence.

CVE-2026-21570
ConfluenceBamboo / Crowd / Fisheye
Mar 17, 2026
High7.9Atlassian

High [CVE-2026-21569] Confluence: This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7.1.0 of Crowd Data Center and…

This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7.1.0 of Crowd Data Center and Server. This XXE (XML External Entity Injection) vulnerability, with a CVSS Score of 7.9, allows an authenticated attacker to access local and remote content which has high impact to confidentiality, low impact to integrity, high impact to availability, and requires no user interaction. Atlassian recommends that Crowd Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: - Crowd Data Center and Server 7.1: Upgrade to a release greater than or equal to 7.1.3 See the release notes ( ). This vulnerability was reported via our Atlassian (Internal) program. Affected products named by the advisory: Confluence.

CVE-2026-21569
ConfluenceBamboo / Crowd / Fisheye
Jan 28, 2026
Medium4.3Atlassian

Medium [CVE-2025-22178] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view items on the "Why" page.

CVE-2025-22178
Jira
Oct 22, 2025
Medium4.3Atlassian

Medium [CVE-2025-22177] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view other team overviews.

CVE-2025-22177
Jira
Oct 22, 2025
Medium4.3Atlassian

Medium [CVE-2025-22176] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view audit log items.

CVE-2025-22176
Jira
Oct 22, 2025
Medium5.4Atlassian

Medium [CVE-2025-22175] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to modify the steps of another user's private checklist.

CVE-2025-22175
Jira
Oct 22, 2025
Medium4.3Atlassian

Medium [CVE-2025-22174] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view portfolio rooms without the required permission.

CVE-2025-22174
Jira
Oct 22, 2025
Medium4.3Atlassian

Medium [CVE-2025-22173] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to view certain sprint data without the required permission.

CVE-2025-22173
Jira
Oct 22, 2025
Medium4.3Atlassian

Medium [CVE-2025-22172] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read external reports without the required permission.

CVE-2025-22172
Jira
Oct 22, 2025
Medium4.3Atlassian

Medium [CVE-2025-22171] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user is able to alter the private checklists of other users.

CVE-2025-22171
Jira
Oct 22, 2025
Medium4.3Atlassian

Medium [CVE-2025-22170] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user without sufficient privileges to perform an action could if they included a particular state-related parameter of a user with sufficient privileges to perform the action.

CVE-2025-22170
Jira
Oct 22, 2025
Medium5.4Atlassian

Medium [CVE-2025-22169] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to subscribe to an item/object without having the expected permission level.

CVE-2025-22169
Jira
Oct 22, 2025
Medium4.3Atlassian

Medium [CVE-2025-22168] Jira: Jira Align is vulnerable to an authorization issue.

Jira Align is vulnerable to an authorization issue. A low-privilege user can access unexpected endpoints that disclose a small amount of sensitive information. For example, a low-level user was able to read the steps of another user's private checklist.

CVE-2025-22168
Jira
Oct 22, 2025

← All vendors