Atlassian security advisory (AV26-731)
Serial number: AV26-731 Date: July 22, 2026 On July 21, 2026, Atlassian published a security advisory to address vulnerabilities, including some critical ones, in the following products: Bamboo Data Center and Server – multiple versions Bitbucket Data Center and Server – multiple versions Confluence Data Center and Server – multiple versions Crowd Data Center and Server – multiple versions Fisheye/Crucible – versions 4.9.0 to 4.9.11 Jira Data Center and Server – multiple versions Jira Service Management Data Center and Server – multiple versions Sourcetree for Mac – all versions from 3.4.11 to 3.4.12 Sourcetree for Windows – all versions from 3.4.11 to 3.4.12 The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. Security Bulletin - July 21 2026 Atlassian Security Advisories and Bulletins
CSIRTS triage
- What
- Atlassian has published a security advisory addressing multiple vulnerabilities across several of its products.
- Who is affected
- Users of affected Atlassian products including Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, Jira, and Sourcetree.
- Urgency
- Remediation is critical due to the presence of multiple critical vulnerabilities.
- Action
- Review the advisory and apply necessary updates to all affected products.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/atlassian-security-advisory-av26-731
More from Canadian Centre for Cyber Security
- unknownGoogle security advisory (AV26-768)2026-07-31
- unknownRails security advisory (AV26-767)2026-07-31
- unknownSolarWinds security advisory (AV26-766)2026-07-31
- unknownGladinet security advisory (AV26-765)2026-07-30
- unknownPHP Group security advisory (AV26-764)2026-07-30