CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Atlassian security advisory (AV26-731)

critical
Serial number: AV26-731 Date: July 22, 2026 On July 21, 2026, Atlassian published a security advisory to address vulnerabilities, including some critical ones, in the following products: Bamboo Data Center and Server – multiple versions Bitbucket Data Center and Server – multiple versions Confluence Data Center and Server – multiple versions Crowd Data Center and Server – multiple versions Fisheye/Crucible – versions 4.9.0 to 4.9.11 Jira Data Center and Server – multiple versions Jira Service Management Data Center and Server – multiple versions Sourcetree for Mac – all versions from 3.4.11 to 3.4.12 Sourcetree for Windows – all versions from 3.4.11 to 3.4.12 The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. Security Bulletin - July 21 2026 Atlassian Security Advisories and Bulletins

CSIRTS triage

vendor: AtlassianOtheraffected: multiple versions
What
Atlassian has published a security advisory addressing multiple vulnerabilities across several of its products.
Who is affected
Users of affected Atlassian products including Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, Jira, and Sourcetree.
Urgency
Remediation is critical due to the presence of multiple critical vulnerabilities.
Action
Review the advisory and apply necessary updates to all affected products.

AI-assisted analysis generated from the source advisory — verify against the original.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
critical
Published
2026-07-22
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/atlassian-security-advisory-av26-731

More from Canadian Centre for Cyber Security