T
Threats
Atlassian Patches Critical And High-Severity Vulnerabilities
Atlassian published its August 2026 Security Bulletin on 18 August 2026, addressing 10 critical-severity and 162 high-severity vulnerability entries. The issues affect Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, Jira Software and Jira Service Management.
Atlassian states that the critical CVSS ratings relate to third-party dependencies and that its use of those components presents a lower, non-critical assessed risk. Organisations should still prioritise upgrades to the latest release or a listed fixed version.
Affected Versions
Bamboo Data Center and Server
Affected: 12.1.0-12.1.9; 12.0.0-12.0.2; 11.0.0-11.0.8; 10.2.0-10.2.21; 10.1.0-10.1.1; 10.0.0-10.0.3
Fixed: 12.1.10 recommended; 10.2.22
Not affected: No additional unaffected versions or configurations were listed.
Bitbucket Data Center and Server
Affected: 10.4.1; 10.3.0-10.3.2; 10.2.0-10.2.5; 10.1.1-10.1.5; 10.0.0-10.0.2; 9.6.0-9.6.5; 9.5.0-9.5.2; 9.4.0-9.4.22; 9.3.0-9.3.2; 9.2.0-9.2.1; 9.1.0-9.1.1
Fixed: 10.4.2; 10.2.6 recommended; 9.4.23
Not affected: No additional unaffected versions or configurations were listed.
Confluence Data Center and Server
Affected: 10.2.0-10.2.14; 10.1.0-10.1.2; 10.0.2-10.0.3; 9.5.1-9.5.4; 9.4.0-9.4.1; 9.3.1-9.3.2; 9.2.0-9.2.22; 9.1.0-9.1.1; 9.0.3; 8.9.6-8.9.8; 8.5.15-8.5.31; 7.19.27-7.19.30
Fixed: 10.2.15 recommended; 9.2.23
Not affected: No additional unaffected versions or configurations were listed.
Crowd Data Center and Server
Affected: 7.2.0-7.2.1; 7.1.0-7.1.5; 7.0.0-7.0.2; 6.3.0-6.3.6; 6.2.0-6.2.6; 6.1.0-6.1.7; 6.0.2-6.0.10
Fixed: 7.2.2-7.2.3 recommended
Not affected: No additional unaffected versions or configurations were listed.
Fisheye and Crucible
Affected: 4.9.0-4.9.12
Fixed: 4.9.13 recommended
Not affected: No additional unaffected versions or configurations were listed.
Jira Software Data Center and Server
Affected: 11.3.0-11.3.8; 11.2.0-11.2.1; 11.1.0-11.1.1; 11.0.0-11.0.1; 10.7.1-10.7.4; 10.6.0-10.6.1; 10.5.0-10.5.1; 10.4.0-10.4.1; 10.3.0-10.3.23; 10.2.0-10.2.1; 10.1.1-10.1.2; 10.0.0-10.0.1; 9.17.3-9.17.5; 9.12.13-9.12.37
Fixed: 11.3.10 recommended; 10.3.24 recommended
Not affected: No additional unaffected versions or configurations were listed.
Jira Service Management Data Center and Server
Affected: 11.3.0-11.3.8; 11.2.0-11.2.1; 11.1.0-11.1.1; 11.0.0-11.0.1; 10.7.1-10.7.4; 10.6.0-10.6.1; 10.5.0-10.5.1; 10.4.0-10.4.1; 10.3.0-10.3.23; 10.2.0-10.2.1; 10.1.1-10.1.2; 10.0.0-10.0.1; 5.17.3-5.17.5
Fixed: 11.3.10 recommended; 10.3.24
Not affected: No additional unaffected versions or configurations were listed.
Source: Jira Service Management Data Center and Server release notes
Vulnerability Breakdown
CVE-2021-44906 - Injection in the minimist dependency
Severity: Critical, CVSS 9.8. Affected: Confluence Data Center and Server. Details: Injection in the minimist dependency. Atlassian assesses lower, non-critical product-context risk for this dependency issue. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.
CVE-2026-4800 - Remote code execution in the lodash dependency
Severity: Critical, CVSS 9.8. Affected: Jira Software Data Center and Server, Jira Service Management Data Center and Server. Details: Remote code execution in the lodash dependency. Atlassian assesses lower, non-critical product-context risk for this dependency issue. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.
CVE-2023-45133 - Arbitrary code execution in the @babel/traverse dependency
Severity: Critical, CVSS 9.3. Affected: Jira Software Data Center and Server. Details: Arbitrary code execution in the @babel/traverse dependency. Atlassian assesses lower, non-critical product-context risk for this dependency issue. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.
CVE-2025-14813 - Security misconfiguration in the Bouncy Castle dependency
Severity: Critical, CVSS 9.3. Affected: Confluence Data Center and Server. Details: Security misconfiguration in the Bouncy Castle dependency. Atlassian assesses lower, non-critical product-context risk for this dependency issue. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.
CVE-2026-59873 - Denial of service in the tar dependency
Severity: Critical, CVSS 9.2. Affected: Confluence Data Center and Server, Jira Software Data Center and Server, Jira Service Management Data Center and Server. Details: Denial of service in the tar dependency. Atlassian assesses lower, non-critical product-context risk for this dependency issue. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.
CVE-2026-2332 - Inconsistent interpretation of HTTP requests in Jetty HTTP
Severity: Critical, CVSS 9.1. Affected: Fisheye and Crucible. Details: Inconsistent interpretation of HTTP requests in Jetty HTTP. Atlassian assesses lower, non-critical product-context risk for this dependency issue. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.
CVE-2026-53434 - Man-in-the-middle weakness in the Tomcat Coyote FFM dependency
Severity: Critical, CVSS 9.1. Affected: Confluence Data Center and Server. Details: Man-in-the-middle weakness in the Tomcat Coyote FFM dependency. Atlassian assesses lower, non-critical product-context risk for this dependency issue. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.
CVE-2026-21582 - Broken authentication and session management
Severity: High, CVSS 8.8. Affected: Crowd Data Center and Server, Jira Software Data Center and Server, Jira Service Management Data Center and Server. Details: Broken authentication and session management. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.
CVE-2026-27606 - File inclusion in rollup
Severity: High, CVSS 8.8. Affected: Jira Software Data Center and Server, Jira Service Management Data Center and Server. Details: File inclusion in rollup. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.
CVE-2026-10050 - Broken authentication and session management in Jetty Security
Severity: High, CVSS 8.7. Affected: Fisheye and Crucible. Details: Broken authentication and session management in Jetty Security. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.
CVE-2026-12143 - Remote code execution in form-data
Severity: High, CVSS 8.7. Affected: Bamboo Data Center and Server, Bitbucket Data Center and Server, Jira Software Data Center and Server, Jira Service Management Data Center and Server. Details: Remote code execution in form-data. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.
CVE-2026-12802 - Cryptographic failure in Bouncy Castle
Severity: High, CVSS 8.7. Affected: Bamboo Data Center and Server. Details: Cryptographic failure in Bouncy Castle. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.
CVE-2026-12803 - Cryptographic failure in Bouncy Castle
Severity: High, CVSS 8.7. Affected: Bamboo Data Center and Server. Details: Cryptographic failure in Bouncy Castle. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.
CVE-2026-12816 - Cryptographic failure in Bouncy Castle
Severity: High, CVSS 8.7. Affected: Bamboo Data Center and Server. Details: Cryptographic failure in Bouncy Castle. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.
CVE-2026-13506 - Denial of service in Bouncy Castle
Severity: High, CVSS 8.7. Affected: Bamboo Data Center and Server. Details: Denial of service in Bouncy Castle. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.
CVE-2026-14682 - Remote code execution in Bouncy Castle
Severity: High, CVSS 8.7. Affected: Bamboo Data Center and Server. Details: Remote code execution in Bouncy Castle. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.
CVE-2026-3505 - Denial of service in Bouncy Castle
Severity: High, CVSS 8.7. Affected: Bitbucket Data Center and Server. Details: Denial of service in Bouncy Castle. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.
CVE-2026-44494 - Injection in Axios
Severity: High, CVSS 8.7. Affected: Crowd Data Center and Server, Jira Software Data Center and Server, Jira Service Management Data Center and Server. Details: Injection in Axios. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.
CVE-2026-48801 - Denial of service in linkify-it
Severity: High, CVSS 8.7. Affected: Confluence Data Center and Server. Details: Denial of service in linkify-it. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.
CVE-2026-55685 - Denial of service in react-router
Severity: High, CVSS 8.7. Affected: Jira Software Data Center and Server, Jira Service Management Data Center and Server. Details: Denial of service in react-router. Atlassian did not specify prerequisites. Upgrade affected products to fixed versions.
CVE-2026-56745 - Denial of service in Netty HTTP
Severity: High, CVSS 8.7. Affected: Bamboo, Crowd, Jira Software and Jira Service Management. Details: Denial of service in Netty HTTP. Upgrade to a fixed version.
CVE-2026-58059 - Bouncy Castle denial of service, High 8.7
CVE-2026-58060 - Bouncy Castle remote code execution, High 8.7
CVE-2026-59639 - Bouncy Castle cryptographic failure, High 8.7
CVE-2026-59642 - Bouncy Castle cryptographic failure, High 8.7
CVE-2026-59874 - tar denial of service, High 8.7
CVE-2026-59901 - Netty codec denial of service, High 8.7
CVE-2026-44492 - Axios SSRF, High 8.6
CVE-2026-0603 - Hibernate SQL injection, High 8.3
CVE-2026-67320 - Axios information disclosure, High 8.3
CVE-2026-27601 - underscore denial of service, High 8.2
CVE-2026-29786 - tar file inclusion, High 8.2
CVE-2026-42041 - Axios injection, High 8.2
CVE-2026-44487 - Axios information disclosure, High 8.2
CVE-2026-44490 - Axios injection, High 8.2
CVE-2026-54291 - PostgreSQL man-in-the-middle weakness, High 8.2
CVE-2026-41907 - uuid remote code execution, High 8.1
CVE-2026-44249 - Netty improper authorisation, High 8.1
CVE-2026-47838 - Spring Security broken authentication, High 8.1
CVE-2026-54512 - Jackson insecure deserialisation, High 8.1
CVE-2026-54513 - Jackson insecure deserialisation, High 8.1
CVE-2026-13149 - brace-expansion denial of service, High 7.7
CVE-2026-69192 - ip-address SSRF, High 7.7
CVE-2022-3517 - minimatch denial of service, High 7.5
CVE-2026-12151 - undici denial of service, High 7.5
CVE-2026-13676 - fast-uri injection, High 7.5
CVE-2026-14257 - brace-expansion denial of service, High 7.5
CVE-2026-16221 - fast-uri injection, High 7.5
CVE-2026-18446 - fast-uri injection, High 7.5
CVE-2026-24734 - Tomcat Coyote injection, High 7.5
CVE-2026-25639 - Axios denial of service, High 7.5
CVE-2026-40983 - Micrometer denial of service, High 7.5
CVE-2026-40984 - Micrometer denial of service, High 7.5
CVE-2026-41284 - Tomcat Catalina denial of service, High 7.5
CVE-2026-41842 - Spring Web MVC denial of service, High 7.5
CVE-2026-41850 - Spring Expression denial of service, High 7.5
CVE-2026-41851 - Spring Expression denial of service, High 7.5
CVE-2026-42198 - PostgreSQL denial of service, High 7.5
CVE-2026-42583 - Netty codec denial of service, High 7.5
CVE-2026-42587 - Netty codec denial of service, High 7.5
CVE-2026-43513 - Tomcat business logic vulnerability, High 7.5
CVE-2026-44486 - Axios information disclosure, High 7.5
CVE-2026-44488 - Axios denial of service, High 7.5
CVE-2026-44496 - Axios denial of service, High 7.5
CVE-2026-45416 - Netty handler denial of service, High 7.5
CVE-2026-45623 - PostCSS information disclosure, High 7.5
CVE-2026-46625 - js-cookie injection, High 7.5
CVE-2026-48043 - Netty HTTP/2 denial of service, High 7.5
CVE-2026-48779 - ws denial of service, High 7.5
CVE-2026-50010 - Netty man-in-the-middle weakness, High 7.5
CVE-2026-55831 - Netty HTTP denial of service, High 7.5
CVE-2026-55833 - Netty HTTP denial of service, High 7.5
CVE-2026-56819 - Netty HTTP/2 denial of service, High 7.5
CVE-2026-59869 - js-yaml denial of service, High 7.5
CVE-2026-59871 - tar denial of service, High 7.5
CVE-2026-59887 - linkify-it denial of service, High 7.5
CVE-2026-6321 - fast-uri file inclusion, High 7.5
CVE-2026-6322 - fast-uri injection, High 7.5
CVE-2026-69152 - brace-expansion denial of service, High 7.5
CVE-2026-42033 - Axios injection, High 7.4
CVE-2026-42035 - Axios injection, High 7.4
CVE-2026-41845 - DOM-based cross-site scripting, High 7.1
CVE-2026-44495 - Axios remote code execution, High 7.0
Mitigation
Upgrade every affected instance to the latest release or a fixed version listed above.
Use the Atlassian Vulnerability Disclosure Portal to check installed versions.
Follow release-specific backup, change-control and upgrade guidance.
Atlassian did not publish a substitute workaround.
Summary for IT Teams
Products: Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, Jira Software and Jira Service Management
Threat Level: Critical by dependency CVSS, with lower product-context risk assessed by Atlassian for critical entries
Action Required: Inventory affected instances and upgrade to the latest or listed fixed versions.
Reference
Need Help?
Secure ISS can help your organisation assess exposure, prioritise upgrades and validate remediation. Contact us on 1300 769 460 or email the Secure ISS team.

