VulnSea

Atlassian has 4 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 7.1 (high). Most affected products: Confluence Data Center (2), Jira Service Management Data Center (1), bamboo (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.1
Publish → KEV
Last 90 days
3 prev 0

Products

  • Confluence Data Center 2
  • Jira Service Management Data Center 1
  • bamboo 1
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

Atlassian vulnerabilities

CVEs affecting Atlassian, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-21588High· 7.1
1w ago

This High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, wit…

This High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, wit…

TwilightAtlassian · Confluence Data CenterEPSS 0.29%via NVD
CVE-2026-21587High· 7.1
1w ago

This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data Center

This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data Center. This Improper Authorization vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to…

TwilightAtlassian · Jira Service Management Data CenterEPSS 0.32%via NVD
CVE-2026-21586High· 7.1
1w ago

This High severity Improper Authorization vulnerability was introduced in versions 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This Improper Authorizatio…

This High severity Improper Authorization vulnerability was introduced in versions 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This Improper Authorizatio…

TwilightAtlassian · Confluence Data CenterEPSS 0.32%via NVD
CVE-2026-21570High· 8.8
6mo ago

This High severity RCE (Remote Code Execution)  vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center. This RCE (Remote Code Execution) vulnerability, with a C…

This High severity RCE (Remote Code Execution)  vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 of Bamboo Data Center. This RCE (Remote Code Execution) vulnerability, with a C…

Twilightatlassian · bambooEPSS 0.57%via NVD
Atlassian vulnerabilities (CVEs) · VulnSea