[UPDATE] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: Multiple vulnerabilities
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
An attacker can exploit multiple vulnerabilities in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira, and Jira Service Management to execute arbitrary code, gain elevated privileges, bypass security measures, manipulate data, disclose confidential information, or trigger a denial-of-service condition.
CSIRTS triage
- What
- Multiple vulnerabilities allow attackers to execute arbitrary code, gain elevated privileges, bypass security measures, manipulate data, disclose confidential information, or trigger a denial-of-service condition.
- Who is affected
- Deployments of Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira, and Jira Service Management are affected.
- Urgency
- Remediation is urgent due to the high severity and active exploitation of these vulnerabilities.
- Action
- Update to the latest versions of the affected Atlassian products.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1955
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2019-112721.4% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 70% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2021-38032.2% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 81% of all EPSS-scored CVEs.
- Exploitation likely imminentCVE-2022-1471EPSS puts this in the most-targeted tier (99.6% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 99.9% of all EPSS-scored CVEs.
- Exploitation confirmedCVE-2022-22965Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.9% of all EPSS-scored CVEs.
- Elevated exploitation riskCVE-2022-2297812.4% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 96% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-316923.4% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 88% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2024-222570.96% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 58% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-222280.59% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-227320.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-247340.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
Referenced CVEs
+1 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Red Hat Enterprise Linux (Apicurio Registry): Multiple Vulnerabilitiescert-bund
- medium[UPDATE] [medium] PostgreSQL JDBC Driver: Vulnerability allows Denial of Servicecert-bund
- unknownNCSC-2026-0325 [1.00] [M/H] Vulnerabilities patched in Atlassian productsncsc-nl
- unknownexploitedMultiple vulnerabilities in IBM products (August 21, 2026)cert-fr-avis
- high[NEW] [high] Splunk SOAR: Multiple vulnerabilitiescert-bund
- highexploited[NEW] [high] Atlassian Products (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, and Jira): Multiple vulnera…cert-bund
- unknownNCSC-2026-0309 [1.00] [M/H] Vulnerabilities resolved in Oracle Communicationsncsc-nl
- unknownNCSC-2026-0306 [1.00] [H/H] Vulnerabilities resolved in Oracle Fusion Middlewarencsc-nl
- high[NEW] [HIGH] Oracle Communications: Multiple Vulnerabilitiescert-bund
- high[NEW] [high] Oracle Fusion Middleware: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] Oracle PeopleSoft: Multiple Vulnerabilitiescert-bund
- high[NEW] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: Mul…cert-bund
Recent advisories for Atlassian Bamboo
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highexploited[NEW] [high] Atlassian Products (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, and Jira): Multiple vulnera…cert-bund · 2026-08-19
- high[NEW] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: Mul…cert-bund · 2026-08-14
- high[UPDATE] [high] Atlassian Bamboo, Bitbucket, Confluence, Jira: Multiple vulnerabilitiescert-bund · 2026-08-03
- high[UPDATE] [high] Atlassian products (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, and Jira): Multiple vuln…cert-bund · 2026-07-20
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] Linux Kernel: Multiple vulnerabilities2026-08-25
- medium[NEW] [medium] libTIFF: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Contao: Multiple Vulnerabilities2026-08-25
- medium[NEW] [medium] Django: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Red Hat Enterprise Linux (Apicurio Registry): Multiple Vulnerabilities2026-08-25