NCSC-2026-0325 [1.00] [M/H] Kwetsbaarheden verholpen in Atlassian producten
Atlassian heeft kwetsbaarheden verholpen in diverse producten zoals Bamboo, Bitbucket, Confluence, Jira, Crowd en Fisheye. De kwetsbaarheden bevinden zich in diverse Third-Party producten waar eerder updates voor zijn verschenen. Atlassian heeft deze updates verwerkt in de eigen producten. Kwaadwillenden kunnen de kwetsbaarheden misbruiken om een Denial-of-Service te veroorzaken, willekeurige code uit te voeren middels het injecteren van scripts of malafide SQL-quieries en/of gegevens te manipuleren of toegang te krijgen tot gevoelige gegevens. Enkele kwetsbaarheden hebben van origine een hoge CVSS score van 9 of meer en zijn door de ontwikkelaars van het kwetsbare product aanvankelijk ingeschaald als 'kritiek'. Door de wijze waarop Atlassian gebruik maakt van deze Third-party modules, is direct misbruik van deze kwetsbaarheden onwaarschijnlijker, waardoor Atlassian de risico's van misbruik voor hun producten lager inschaalt. Echter, door de grote hoeveelheid verholpen kwetsbaarheden adviseert het NCSC wel om deze updates met voorrang in te zetten, met name op systemen die toegankelijk zijn vanaf publieke infrastructuur.
CSIRTS triage
- What
- Atlassian products have incorporated patches for third-party component vulnerabilities affecting Bamboo, Bitbucket, Confluence, Jira, Crowd, and Fisheye, including RCE, DoS, SQL injection, and data manipulation risks.
- Who is affected
- Deployments of Atlassian Bamboo, Bitbucket, Confluence, Jira, Crowd, and Fisheye using unpatched versions.
- Urgency
- High urgency due to originally critical-rated vulnerabilities; direct exploitation risk is reduced by Atlassian's architecture but defense-in-depth patching is essential.
- Action
- Apply available security updates to all affected Atlassian products.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0325
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2021-449064.6% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 91% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-35171.8% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 77% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2023-451330.52% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-148130.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-06030.80% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 54% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-23321.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 69% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-35050.79% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 54% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-48002.8% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 85% of all EPSS-scored CVEs.
- Elevated exploitation riskCVE-2021-2333721.3% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 97% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-63210.63% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 48% of all EPSS-scored CVEs.
Referenced CVEs
+12 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [hoch] Netty: Mehrere Schwachstellencert-bund
- medium[UPDATE] [mittel] PostgreSQL JDBC Driver: Schwachstelle ermöglicht Denial of Servicecert-bund
- medium[UPDATE] [mittel] Netty: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Red Hat Enterprise Linux und Satellite (satellite/iop-remediations-rhel9 container image): Meh…cert-bund
- high[UPDATE] [hoch] Bouncy Castle BC-JAVA: Mehrere Schwachstellencert-bund
- high[NEU] [hoch] IBM MQ Appliance (Axios Node.js): Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Red Hat Enterprise Linux (Apicurio Registry): Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] IBM License Metric Tool: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Red Hat Enterprise Linux (nodejs:24): Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Red Hat Ansible Automation Platform (node-tar, linkify-it, protobufjs, brace-expansion, fast-u…cert-bund
- medium[UPDATE] [mittel] Red Hat OpenShift Container Platform (fast-uri,OpenTelemetry-Go) : Mehrere Schwachstellencert-bund
- medium[UPDATE] [mittel] Eclipse Jetty: Mehrere Schwachstellencert-bund
Recent advisories for Kwetsbaarheden verholpen in
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownNCSC-2026-0366 [1.00] [M/H] Kwetsbaarheden verholpen in Arista EOSncsc-nl · 2026-09-11
- unknownNCSC-2026-0365 [1.00] [H/H] Kwetsbaarheden verholpen in Check Point VPN productenncsc-nl · 2026-09-10
- unknownNCSC-2026-0364 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Illustratorncsc-nl · 2026-09-09
- unknownNCSC-2026-0363 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Experience Managerncsc-nl · 2026-09-09
- unknownNCSC-2026-0362 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe ColdFusionncsc-nl · 2026-09-09
- unknownNCSC-2026-0361 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Commercencsc-nl · 2026-09-09
More from NCSC-NL Advisories
- unknownNCSC-2026-0366 [1.00] [M/H] Kwetsbaarheden verholpen in Arista EOS2026-09-11
- unknownNCSC-2026-0015 [1.01] [M/H] Kwetsbaarheid verholpen in Fortinet FortiOS2026-09-10
- unknownNCSC-2026-0365 [1.00] [H/H] Kwetsbaarheden verholpen in Check Point VPN producten2026-09-10
- unknownNCSC-2026-0364 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Illustrator2026-09-09
- unknownNCSC-2026-0363 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Experience Manager2026-09-09