[UPDATE] [high] Atlassian Bamboo, Bitbucket, Confluence, Jira: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence and Atlassian Jira to execute arbitrary code, bypass security measures, manipulate or disclose data, or conduct cross-site scripting attacks.
CSIRTS triage
- What
- Multiple vulnerabilities across Atlassian products (Bamboo, Bitbucket, Confluence, Jira) enable code execution, auth bypass, XSS, and data manipulation.
- Who is affected
- Organisations running Atlassian Bamboo, Bitbucket, Confluence, or Jira are affected.
- Urgency
- High severity with multiple attack vectors and critical impact on confidentiality, integrity, and availability.
- Action
- Apply Atlassian security patches for all affected products immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1229
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2021-03410.88% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 56% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2021-315972.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 80% of all EPSS-scored CVEs.
- Exploitation likely imminentCVE-2022-1471EPSS puts this in the most-targeted tier (99.6% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 99.9% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-259271.7% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 75% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2023-13701.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 63% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2023-36351.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 67% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2023-486311.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 63% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2024-293710.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2024-458010.84% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 55% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2024-478751.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 62% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highexploited[UPDATE] [hoch] Apache Tomcat und Tomcat Native: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Splunk SOAR: Mehrere Schwachstellencert-bund
- highexploited[UPDATE] [hoch] Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, und Jira): Mehrere Schwa…cert-bund
- high[UPDATE] [hoch] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: …cert-bund
- unknownMultiples vulnérabilités dans les produits IBM (04 septembre 2026)cert-fr-avis
- high[NEW] [high] Oracle Siebel CRM: Multiple vulnerabilitiescert-bund
- highexploited[UPDATE] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: …cert-bund
- high[UPDATE] [high] IBM License Metric Tool: Multiple Vulnerabilities enable unspecified attackcert-bund
- high[UPDATE] [high] Apache Tomcat and Tomcat Native: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] Red Hat Ansible Automation Platform: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] Netty: Multiple vulnerabilitiescert-bund
- high[NEW] [high] IBM Concert: Multiple vulnerabilitiescert-bund
Recent advisories for Atlassian Bamboo
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highexploited[UPDATE] [hoch] Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, und Jira): Mehrere Schwa…cert-bund · 2026-09-04
- high[UPDATE] [hoch] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: …cert-bund · 2026-09-04
- highexploited[UPDATE] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: …cert-bund · 2026-09-02
- high[UPDATE] [high] Atlassian products (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, and Jira): Multiple vuln…cert-bund · 2026-07-20
More from CERT-Bund (BSI) Security Advisories
- medium[NEU] [mittel] Langflow: Mehrere Schwachstellen2026-09-04
- low[NEU] [niedrig] Checkmk: Schwachstelle ermöglicht Denial of Service2026-09-04
- medium[NEU] [mittel] Grafana Enterprise: Mehrere Schwachstellen ermöglichen Erlangen von Benutzer- oder Administrato…2026-09-04
- low[NEU] [niedrig] ImageMagick: Mehrere Schwachstellen ermöglichen Denial of Service2026-09-04
- critical[NEU] [kritisch] vm2: Mehrere Schwachstellen ermöglichen Codeausführung2026-09-04