CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0325 [1.00] [M/H] Kwetsbaarheden verholpen in Atlassian producten

unknownCVE-2021-44906CVE-2022-3517CVE-2023-45133CVE-2025-14813CVE-2026-0603CVE-2026-2332
Atlassian heeft kwetsbaarheden verholpen in diverse producten zoals Bamboo, Bitbucket, Confluence, Jira, Crowd en Fisheye. De kwetsbaarheden bevinden zich in diverse Third-Party producten waar eerder updates voor zijn verschenen. Atlassian heeft deze updates verwerkt in de eigen producten. Kwaadwillenden kunnen de kwetsbaarheden misbruiken om een Denial-of-Service te veroorzaken, willekeurige code uit te voeren middels het injecteren van scripts of malafide SQL-quieries en/of gegevens te manipuleren of toegang te krijgen tot gevoelige gegevens. Enkele kwetsbaarheden hebben van origine een hoge CVSS score van 9 of meer en zijn door de ontwikkelaars van het kwetsbare product aanvankelijk ingeschaald als 'kritiek'. Door de wijze waarop Atlassian gebruik maakt van deze Third-party modules, is direct misbruik van deze kwetsbaarheden onwaarschijnlijker, waardoor Atlassian de risico's van misbruik voor hun producten lager inschaalt. Echter, door de grote hoeveelheid verholpen kwetsbaarheden adviseert het NCSC wel om deze updates met voorrang in te zetten, met name op systemen die toegankelijk zijn vanaf publieke infrastructuur.

CSIRTS triage

What
Atlassian products have incorporated patches for third-party component vulnerabilities affecting Bamboo, Bitbucket, Confluence, Jira, Crowd, and Fisheye, including RCE, DoS, SQL injection, and data manipulation risks.
Who is affected
Deployments of Atlassian Bamboo, Bitbucket, Confluence, Jira, Crowd, and Fisheye using unpatched versions.
Urgency
High urgency due to originally critical-rated vulnerabilities; direct exploitation risk is reduced by Atlassian's architecture but defense-in-depth patching is essential.
Action
Apply available security updates to all affected Atlassian products.

AI-assisted analysis generated from the source advisory — verify against the original.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-08-24
Exploitation
Not in CISA KEV at last sync

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0325

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2021-44906coverage & exploitation statusNVD · CVE.org
CVE-2022-3517coverage & exploitation statusNVD · CVE.org
CVE-2023-45133coverage & exploitation statusNVD · CVE.org
CVE-2025-14813coverage & exploitation statusNVD · CVE.org
CVE-2026-0603coverage & exploitation statusNVD · CVE.org
CVE-2026-2332coverage & exploitation statusNVD · CVE.org
CVE-2026-3505coverage & exploitation statusNVD · CVE.org
CVE-2026-4800coverage & exploitation statusNVD · CVE.org
CVE-2021-23337coverage & exploitation statusNVD · CVE.org
CVE-2026-6321coverage & exploitation statusNVD · CVE.org
CVE-2026-6322coverage & exploitation statusNVD · CVE.org
CVE-2026-10050coverage & exploitation statusNVD · CVE.org
CVE-2026-12143coverage & exploitation statusNVD · CVE.org
CVE-2026-12151coverage & exploitation statusNVD · CVE.org
CVE-2026-12802coverage & exploitation statusNVD · CVE.org
CVE-2026-12803coverage & exploitation statusNVD · CVE.org
CVE-2026-12816coverage & exploitation statusNVD · CVE.org
CVE-2026-13149coverage & exploitation statusNVD · CVE.org
CVE-2026-13506coverage & exploitation statusNVD · CVE.org
CVE-2026-13676coverage & exploitation statusNVD · CVE.org
CVE-2026-14257coverage & exploitation statusNVD · CVE.org
CVE-2026-14682coverage & exploitation statusNVD · CVE.org
CVE-2026-16221coverage & exploitation statusNVD · CVE.org
CVE-2026-18446coverage & exploitation statusNVD · CVE.org
CVE-2026-21582coverage & exploitation statusNVD · CVE.org
CVE-2026-24734coverage & exploitation statusNVD · CVE.org
CVE-2026-25639coverage & exploitation statusNVD · CVE.org
CVE-2026-27601coverage & exploitation statusNVD · CVE.org
CVE-2026-27606coverage & exploitation statusNVD · CVE.org
CVE-2026-29786coverage & exploitation statusNVD · CVE.org
CVE-2026-40983coverage & exploitation statusNVD · CVE.org
CVE-2026-40984coverage & exploitation statusNVD · CVE.org
CVE-2026-41284coverage & exploitation statusNVD · CVE.org
CVE-2026-41842coverage & exploitation statusNVD · CVE.org
CVE-2026-41845coverage & exploitation statusNVD · CVE.org
CVE-2026-41850coverage & exploitation statusNVD · CVE.org
CVE-2026-41851coverage & exploitation statusNVD · CVE.org
CVE-2026-41907coverage & exploitation statusNVD · CVE.org
CVE-2026-42033coverage & exploitation statusNVD · CVE.org
CVE-2026-42035coverage & exploitation statusNVD · CVE.org
CVE-2026-42041coverage & exploitation statusNVD · CVE.org
CVE-2026-42198coverage & exploitation statusNVD · CVE.org
CVE-2026-42583coverage & exploitation statusNVD · CVE.org
CVE-2026-42587coverage & exploitation statusNVD · CVE.org
CVE-2026-43513coverage & exploitation statusNVD · CVE.org
CVE-2026-44249coverage & exploitation statusNVD · CVE.org
CVE-2026-44486coverage & exploitation statusNVD · CVE.org
CVE-2026-44487coverage & exploitation statusNVD · CVE.org

+12 more CVEs referenced in this advisory.

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Kwetsbaarheden verholpen in

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from NCSC-NL Advisories