T

Threats

Atlassian Patches Critical And High-Severity Vulnerabilities

Atlassian published its August 2026 Security Bulletin on 18 August 2026, addressing 10 critical-severity and 162 high-severity vulnerability entries. The issues affect Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, Jira Software and Jira Service Management.

Atlassian states that the critical CVSS ratings relate to third-party dependencies and that its use of those components presents a lower, non-critical assessed risk. Organisations should still prioritise upgrades to the latest release or a listed fixed version.


Affected Versions

Bamboo Data Center and Server

  • Affected: 12.1.0-12.1.9; 12.0.0-12.0.2; 11.0.0-11.0.8; 10.2.0-10.2.21; 10.1.0-10.1.1; 10.0.0-10.0.3

  • Fixed: 12.1.10 recommended; 10.2.22

  • Not affected: No additional unaffected versions or configurations were listed.

  • Source: Bamboo Data Center and Server release notes

Bitbucket Data Center and Server

  • Affected: 10.4.1; 10.3.0-10.3.2; 10.2.0-10.2.5; 10.1.1-10.1.5; 10.0.0-10.0.2; 9.6.0-9.6.5; 9.5.0-9.5.2; 9.4.0-9.4.22; 9.3.0-9.3.2; 9.2.0-9.2.1; 9.1.0-9.1.1

  • Fixed: 10.4.2; 10.2.6 recommended; 9.4.23

  • Not affected: No additional unaffected versions or configurations were listed.

  • Source: Bitbucket Data Center and Server release notes

Confluence Data Center and Server

  • Affected: 10.2.0-10.2.14; 10.1.0-10.1.2; 10.0.2-10.0.3; 9.5.1-9.5.4; 9.4.0-9.4.1; 9.3.1-9.3.2; 9.2.0-9.2.22; 9.1.0-9.1.1; 9.0.3; 8.9.6-8.9.8; 8.5.15-8.5.31; 7.19.27-7.19.30

  • Fixed: 10.2.15 recommended; 9.2.23

  • Not affected: No additional unaffected versions or configurations were listed.

  • Source: Confluence Data Center and Server release notes

Crowd Data Center and Server

  • Affected: 7.2.0-7.2.1; 7.1.0-7.1.5; 7.0.0-7.0.2; 6.3.0-6.3.6; 6.2.0-6.2.6; 6.1.0-6.1.7; 6.0.2-6.0.10

  • Fixed: 7.2.2-7.2.3 recommended

  • Not affected: No additional unaffected versions or configurations were listed.

  • Source: Crowd Data Center and Server release notes

Fisheye and Crucible

Jira Software Data Center and Server

  • Affected: 11.3.0-11.3.8; 11.2.0-11.2.1; 11.1.0-11.1.1; 11.0.0-11.0.1; 10.7.1-10.7.4; 10.6.0-10.6.1; 10.5.0-10.5.1; 10.4.0-10.4.1; 10.3.0-10.3.23; 10.2.0-10.2.1; 10.1.1-10.1.2; 10.0.0-10.0.1; 9.17.3-9.17.5; 9.12.13-9.12.37

  • Fixed: 11.3.10 recommended; 10.3.24 recommended

  • Not affected: No additional unaffected versions or configurations were listed.

  • Source: Jira Software Data Center and Server release notes

Jira Service Management Data Center and Server

  • Affected: 11.3.0-11.3.8; 11.2.0-11.2.1; 11.1.0-11.1.1; 11.0.0-11.0.1; 10.7.1-10.7.4; 10.6.0-10.6.1; 10.5.0-10.5.1; 10.4.0-10.4.1; 10.3.0-10.3.23; 10.2.0-10.2.1; 10.1.1-10.1.2; 10.0.0-10.0.1; 5.17.3-5.17.5

  • Fixed: 11.3.10 recommended; 10.3.24

  • Not affected: No additional unaffected versions or configurations were listed.

  • Source: Jira Service Management Data Center and Server release notes

Vulnerability Breakdown

CVE-2021-44906 - Injection in the minimist dependency

  • Severity: Critical, CVSS 9.8. Affected: Confluence Data Center and Server. Details: Injection in the minimist dependency. Atlassian assesses lower, non-critical product-context risk for this dependency issue. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.

CVE-2026-4800 - Remote code execution in the lodash dependency

  • Severity: Critical, CVSS 9.8. Affected: Jira Software Data Center and Server, Jira Service Management Data Center and Server. Details: Remote code execution in the lodash dependency. Atlassian assesses lower, non-critical product-context risk for this dependency issue. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.

CVE-2023-45133 - Arbitrary code execution in the @babel/traverse dependency

  • Severity: Critical, CVSS 9.3. Affected: Jira Software Data Center and Server. Details: Arbitrary code execution in the @babel/traverse dependency. Atlassian assesses lower, non-critical product-context risk for this dependency issue. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.

CVE-2025-14813 - Security misconfiguration in the Bouncy Castle dependency

  • Severity: Critical, CVSS 9.3. Affected: Confluence Data Center and Server. Details: Security misconfiguration in the Bouncy Castle dependency. Atlassian assesses lower, non-critical product-context risk for this dependency issue. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.

CVE-2026-59873 - Denial of service in the tar dependency

  • Severity: Critical, CVSS 9.2. Affected: Confluence Data Center and Server, Jira Software Data Center and Server, Jira Service Management Data Center and Server. Details: Denial of service in the tar dependency. Atlassian assesses lower, non-critical product-context risk for this dependency issue. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.

CVE-2026-2332 - Inconsistent interpretation of HTTP requests in Jetty HTTP

  • Severity: Critical, CVSS 9.1. Affected: Fisheye and Crucible. Details: Inconsistent interpretation of HTTP requests in Jetty HTTP. Atlassian assesses lower, non-critical product-context risk for this dependency issue. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.

CVE-2026-53434 - Man-in-the-middle weakness in the Tomcat Coyote FFM dependency

  • Severity: Critical, CVSS 9.1. Affected: Confluence Data Center and Server. Details: Man-in-the-middle weakness in the Tomcat Coyote FFM dependency. Atlassian assesses lower, non-critical product-context risk for this dependency issue. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.

CVE-2026-21582 - Broken authentication and session management

  • Severity: High, CVSS 8.8. Affected: Crowd Data Center and Server, Jira Software Data Center and Server, Jira Service Management Data Center and Server. Details: Broken authentication and session management. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.

CVE-2026-27606 - File inclusion in rollup

  • Severity: High, CVSS 8.8. Affected: Jira Software Data Center and Server, Jira Service Management Data Center and Server. Details: File inclusion in rollup. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.

CVE-2026-10050 - Broken authentication and session management in Jetty Security

  • Severity: High, CVSS 8.7. Affected: Fisheye and Crucible. Details: Broken authentication and session management in Jetty Security. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.

CVE-2026-12143 - Remote code execution in form-data

  • Severity: High, CVSS 8.7. Affected: Bamboo Data Center and Server, Bitbucket Data Center and Server, Jira Software Data Center and Server, Jira Service Management Data Center and Server. Details: Remote code execution in form-data. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.

CVE-2026-12802 - Cryptographic failure in Bouncy Castle

  • Severity: High, CVSS 8.7. Affected: Bamboo Data Center and Server. Details: Cryptographic failure in Bouncy Castle. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.

CVE-2026-12803 - Cryptographic failure in Bouncy Castle

  • Severity: High, CVSS 8.7. Affected: Bamboo Data Center and Server. Details: Cryptographic failure in Bouncy Castle. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.

CVE-2026-12816 - Cryptographic failure in Bouncy Castle

  • Severity: High, CVSS 8.7. Affected: Bamboo Data Center and Server. Details: Cryptographic failure in Bouncy Castle. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.

CVE-2026-13506 - Denial of service in Bouncy Castle

  • Severity: High, CVSS 8.7. Affected: Bamboo Data Center and Server. Details: Denial of service in Bouncy Castle. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.

CVE-2026-14682 - Remote code execution in Bouncy Castle

  • Severity: High, CVSS 8.7. Affected: Bamboo Data Center and Server. Details: Remote code execution in Bouncy Castle. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.

CVE-2026-3505 - Denial of service in Bouncy Castle

  • Severity: High, CVSS 8.7. Affected: Bitbucket Data Center and Server. Details: Denial of service in Bouncy Castle. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.

CVE-2026-44494 - Injection in Axios

  • Severity: High, CVSS 8.7. Affected: Crowd Data Center and Server, Jira Software Data Center and Server, Jira Service Management Data Center and Server. Details: Injection in Axios. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.

CVE-2026-48801 - Denial of service in linkify-it

  • Severity: High, CVSS 8.7. Affected: Confluence Data Center and Server. Details: Denial of service in linkify-it. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.

CVE-2026-55685 - Denial of service in react-router

  • Severity: High, CVSS 8.7. Affected: Jira Software Data Center and Server, Jira Service Management Data Center and Server. Details: Denial of service in react-router. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.

CVE-2026-56745 - Denial of service in Netty HTTP

  • Severity: High, CVSS 8.7. Affected: Bamboo, Crowd, Jira Software and Jira Service Management. Details: Denial of service in Netty HTTP. Upgrade to a fixed version.

CVE-2026-58059 - Bouncy Castle denial of service, High 8.7

CVE-2026-58060 - Bouncy Castle remote code execution, High 8.7

CVE-2026-59639 - Bouncy Castle cryptographic failure, High 8.7

CVE-2026-59642 - Bouncy Castle cryptographic failure, High 8.7

CVE-2026-59874 - tar denial of service, High 8.7

CVE-2026-59901 - Netty codec denial of service, High 8.7

CVE-2026-44492 - Axios SSRF, High 8.6

CVE-2026-0603 - Hibernate SQL injection, High 8.3

CVE-2026-67320 - Axios information disclosure, High 8.3

CVE-2026-27601 - underscore denial of service, High 8.2

CVE-2026-29786 - tar file inclusion, High 8.2

CVE-2026-42041 - Axios injection, High 8.2

CVE-2026-44487 - Axios information disclosure, High 8.2

CVE-2026-44490 - Axios injection, High 8.2

CVE-2026-54291 - PostgreSQL man-in-the-middle weakness, High 8.2

CVE-2026-41907 - uuid remote code execution, High 8.1

CVE-2026-44249 - Netty improper authorisation, High 8.1

CVE-2026-47838 - Spring Security broken authentication, High 8.1

CVE-2026-54512 - Jackson insecure deserialisation, High 8.1

CVE-2026-54513 - Jackson insecure deserialisation, High 8.1

CVE-2026-13149 - brace-expansion denial of service, High 7.7

CVE-2026-69192 - ip-address SSRF, High 7.7

CVE-2022-3517 - minimatch denial of service, High 7.5

CVE-2026-12151 - undici denial of service, High 7.5

CVE-2026-13676 - fast-uri injection, High 7.5

CVE-2026-14257 - brace-expansion denial of service, High 7.5

CVE-2026-16221 - fast-uri injection, High 7.5

CVE-2026-18446 - fast-uri injection, High 7.5

CVE-2026-24734 - Tomcat Coyote injection, High 7.5

CVE-2026-25639 - Axios denial of service, High 7.5

CVE-2026-40983 - Micrometer denial of service, High 7.5

CVE-2026-40984 - Micrometer denial of service, High 7.5

CVE-2026-41284 - Tomcat Catalina denial of service, High 7.5

CVE-2026-41842 - Spring Web MVC denial of service, High 7.5

CVE-2026-41850 - Spring Expression denial of service, High 7.5

CVE-2026-41851 - Spring Expression denial of service, High 7.5

CVE-2026-42198 - PostgreSQL denial of service, High 7.5

CVE-2026-42583 - Netty codec denial of service, High 7.5

CVE-2026-42587 - Netty codec denial of service, High 7.5

CVE-2026-43513 - Tomcat business logic vulnerability, High 7.5

CVE-2026-44486 - Axios information disclosure, High 7.5

CVE-2026-44488 - Axios denial of service, High 7.5

CVE-2026-44496 - Axios denial of service, High 7.5

CVE-2026-45416 - Netty handler denial of service, High 7.5

CVE-2026-45623 - PostCSS information disclosure, High 7.5

CVE-2026-46625 - js-cookie injection, High 7.5

CVE-2026-48043 - Netty HTTP/2 denial of service, High 7.5

CVE-2026-48779 - ws denial of service, High 7.5

CVE-2026-50010 - Netty man-in-the-middle weakness, High 7.5

CVE-2026-55831 - Netty HTTP denial of service, High 7.5

CVE-2026-55833 - Netty HTTP denial of service, High 7.5

CVE-2026-56819 - Netty HTTP/2 denial of service, High 7.5

CVE-2026-59869 - js-yaml denial of service, High 7.5

CVE-2026-59871 - tar denial of service, High 7.5

CVE-2026-59887 - linkify-it denial of service, High 7.5

CVE-2026-6321 - fast-uri file inclusion, High 7.5

CVE-2026-6322 - fast-uri injection, High 7.5

CVE-2026-69152 - brace-expansion denial of service, High 7.5

CVE-2026-42033 - Axios injection, High 7.4

CVE-2026-42035 - Axios injection, High 7.4

CVE-2026-41845 - DOM-based cross-site scripting, High 7.1

CVE-2026-44495 - Axios remote code execution, High 7.0


Mitigation

  • Upgrade every affected instance to the latest release or a fixed version listed above.

  • Use the Atlassian Vulnerability Disclosure Portal to check installed versions.

  • Follow release-specific backup, change-control and upgrade guidance.

  • Atlassian did not publish a substitute workaround.


Summary for IT Teams

  • Products: Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, Jira Software and Jira Service Management

  • Threat Level: Critical by dependency CVSS, with lower product-context risk assessed by Atlassian for critical entries

  • Action Required: Inventory affected instances and upgrade to the latest or listed fixed versions.


Reference


Need Help?

Secure ISS can help your organisation assess exposure, prioritise upgrades and validate remediation. Contact us on 1300 769 460 or email the Secure ISS team.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.