Atlassian Vulnerabilities
Atlassian makes team collaboration software, and its KEV entries involve self-managed Confluence, Jira, Bitbucket and Crowd deployments. The database tracks 13 Atlassian CVE records. CISA lists 13 of them as exploited in the wild, most recently on 2024-11-12. The most affected products are Confluence Data Center and Server, Confluence Server and Data Center, Jira Server and Data Center.
Recently Exploited Atlassian CVEs
Atlassian Jira Server and Data Center Path Traversal Vulnerability
Atlassian Confluence Data Center and Server Template Injection Vulnerability
Atlassian Confluence Data Center and Server Improper Authorization Vulnerability
Atlassian Confluence Data Center and Server Broken Access Control Vulnerability
Atlassian Bitbucket Server and Data Center Command Injection Vulnerability
Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability
Affected Products
9 products| Product | CVEs | KEV | Latest |
|---|---|---|---|
| Confluence Data Center and Server | 3 | 3 | 2024-01-24 |
| Confluence Server and Data Center | 2 | 2 | 2021-11-03 |
| Jira Server and Data Center | 2 | 2 | 2024-11-12 |
| Bitbucket Server and Data Center | 1 | 1 | 2022-09-30 |
| Confluence | 1 | 1 | 2022-07-29 |
| Confluence Server | 1 | 1 | 2022-03-28 |
| Confluence Server and Data Server | 1 | 1 | 2021-11-03 |
| Confluence Server/Data Center | 1 | 1 | 2022-06-02 |
| Crowd and Crowd Data Center | 1 | 1 | 2021-11-03 |
All Atlassian CVEs
13 records| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2021-26086 | Atlassian Jira Server and Data Center Path Traversal Vulnerability | Atlassian | 5.3 | 100.0% | KEV | 2021-08-16 |
| CVE-2023-22527 | Atlassian Confluence Data Center and Server Template Injection Vulnerability | Atlassian | 10.0 | 100.0% | KEV | 2024-01-16 |
| CVE-2023-22518 | Atlassian Confluence Data Center and Server Improper Authorization Vulnerability | Atlassian | 10.0 | 100.0% | KEV | 2023-10-31 |
| CVE-2023-22515 | Atlassian Confluence Data Center and Server Broken Access Control Vulnerability | Atlassian | 10.0 | 99.2% | KEV | 2023-10-04 |
| CVE-2022-36804 | Atlassian Bitbucket Server and Data Center Command Injection Vulnerability | Atlassian | 8.8 | 99.2% | KEV | 2022-08-25 |
| CVE-2022-26138 | Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability | Atlassian | 9.8 | 98.2% | KEV | 2022-07-20 |
| CVE-2022-26134 | Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability | Atlassian | 9.8 | 100.0% | KEV | 2022-06-03 |
| CVE-2021-26085 | Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability | Atlassian | 5.3 | 99.9% | KEV | 2021-08-03 |
| CVE-2019-11581 | Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability | Atlassian | 9.8 | 84.6% | KEV | 2019-08-09 |
| CVE-2021-26084 | Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability | Atlassian | 9.8 | 100.0% | KEV | 2021-08-30 |
| CVE-2019-3396 | Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability | Atlassian | 9.8 | 99.9% | KEV | 2019-03-25 |
| CVE-2019-3398 | Atlassian Confluence Server and Data Center Path Traversal Vulnerability | Atlassian | 8.8 | 97.0% | KEV | 2019-04-18 |
| CVE-2019-11580 | Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability | Atlassian | 9.8 | 95.4% | KEV | 2019-06-03 |
Frequently Asked Questions
How many Atlassian vulnerabilities are actively exploited?→
13 Atlassian CVEs are in the CISA Known Exploited Vulnerabilities catalog as of 2026-10-09. The latest was added on 2024-11-12.
Which Atlassian vulnerabilities are used in ransomware attacks?→
CISA marks 8 Atlassian KEV entries as known to be used in ransomware campaigns, including CVE-2023-22527, CVE-2023-22518, CVE-2023-22515, CVE-2022-26134, CVE-2021-26085.
Which Atlassian products have the most exploited vulnerabilities?→
- +Confluence Data Center and Server: 3 CVEs (3 in KEV)
- +Confluence Server and Data Center: 2 CVEs (2 in KEV)
- +Jira Server and Data Center: 2 CVEs (2 in KEV)
- +Bitbucket Server and Data Center: 1 CVE (1 in KEV)
- +Confluence: 1 CVE (1 in KEV)
Where does Atlassian publish security advisories?→
Atlassian publishes security advisories at https://www.atlassian.com/trust/security/advisories. Check the vendor advisory for fixed versions and workarounds before applying updates.
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Vendor and product names for exploited CVEs follow the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not affiliated with or endorsed by Atlassian, MITRE, CISA, or FIRST.