[NEW] [high] Atlassian Products (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, and Jira): Multiple vulnerabilities
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
An attacker can exploit multiple vulnerabilities in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence, Atlassian Crucible, Atlassian Fisheye and Atlassian Jira to execute arbitrary code, conduct a denial of service attack, disclose information, manipulate files, conduct a cross-site scripting attack, conduct a SQL injection attack, and bypass security measures.
CSIRTS triage
- What
- Multiple vulnerabilities in Atlassian products allow remote code execution, denial of service, information disclosure, cross-site scripting, SQL injection, and security bypass.
- Who is affected
- Atlassian Bamboo, Bitbucket, Confluence, Crucible, Fisheye, and Jira deployments across multiple versions.
- Urgency
- High priority; vulnerabilities are actively being exploited in the wild.
- Action
- Apply security patches for each affected product as provided by Atlassian immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2923
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Elevated exploitation riskCVE-2019-1399016.2% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 97% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2021-449064.6% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 91% of all EPSS-scored CVEs.
- Exploitation likely imminentCVE-2022-1471EPSS puts this in the most-targeted tier (99.6% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 99.9% of all EPSS-scored CVEs.
- Exploitation likely imminentCVE-2022-23521EPSS puts this in the most-targeted tier (56.3% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 99% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-35171.8% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 77% of all EPSS-scored CVEs.
- Elevated exploitation riskCVE-2022-4190344.3% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 99% of all EPSS-scored CVEs.
- Exploitation confirmedCVE-2023-22518Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.9% of all EPSS-scored CVEs.
- Elevated exploitation riskCVE-2023-2252212.8% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 96% of all EPSS-scored CVEs.
- Elevated exploitation riskCVE-2023-2252311.1% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 96% of all EPSS-scored CVEs.
- Elevated exploitation riskCVE-2023-2252424.7% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 98% of all EPSS-scored CVEs.
- Exploitation confirmedCVE-2023-22527Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] IBM App Connect Enterprise: Multiple vulnerabilitiescert-bund
- unknownNCSC-2026-0311 [1.00] [M/H] Vulnerabilities resolved in Oracle Enterprise Managerncsc-nl
- unknownNCSC-2026-0309 [1.00] [M/H] Vulnerabilities resolved in Oracle Communicationsncsc-nl
- high[NEW] [high] Red Hat Enterprise Linux (nodejs:24): Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Red Hat OpenShift Container Platform (fast-uri, OpenTelemetry-Go): Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] Red Hat OpenShift Container Platform (protobufjs, fast-uri): Multiple vulnerabilitiescert-bund
- unknownNCSC-2026-0306 [1.00] [H/H] Vulnerabilities resolved in Oracle Fusion Middlewarencsc-nl
- high[NEW] [HIGH] Oracle Communications: Multiple Vulnerabilitiescert-bund
- high[NEW] [high] Oracle Enterprise Manager: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Fusion Middleware: Multiple vulnerabilitiescert-bund
- unknownCVE-2026-21582: This High severity BASM (Broken Authentication & Session Management) vulnerability known as CV…nvd
- medium[NEW] [medium] Eclipse Jetty: Multiple vulnerabilitiescert-bund
Recent advisories for Atlassian Products
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-73498: MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and …nvd · 2026-08-12
- unknownMultiple vulnerabilities in Atlassian products (July 27, 2026)cert-fr-avis · 2026-07-27
- high[UPDATE] [high] Atlassian products (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, and Jira): Multiple vuln…cert-bund · 2026-07-20
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] Joomla: Multiple vulnerabilities2026-08-19
- medium[NEW] [medium] Axis Axis OS: Multiple vulnerabilities2026-08-19
- medium[NEW] [medium] CPython: Multiple vulnerabilities2026-08-19
- high[NEW] [high] Microsoft Developer Tools: Multiple Vulnerabilities2026-08-19
- medium[NEW] [medium] Nvidia Cumulus Linux: Multiple vulnerabilities2026-08-19