[UPDATE] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: Multiple vulnerabilities
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
An attacker can exploit multiple vulnerabilities in Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira, and Jira Service Management to execute arbitrary code, gain elevated privileges, bypass security measures, manipulate data, disclose confidential information, or trigger a denial-of-service condition.
CSIRTS triage
- What
- Multiple vulnerabilities allow attackers to execute arbitrary code, gain elevated privileges, bypass security measures, manipulate data, disclose confidential information, or trigger a denial-of-service condition.
- Who is affected
- Deployments of Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira, and Jira Service Management are affected.
- Urgency
- Remediation is urgent due to the high severity and active exploitation of these vulnerabilities.
- Action
- Update to the latest versions of the affected Atlassian products.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1955
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Moderate exploitation riskCVE-2019-112721.4% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 71% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2021-38032.2% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 81% of all EPSS-scored CVEs.
- Exploitation likely imminentCVE-2022-1471EPSS puts this in the most-targeted tier (99.6% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 99.9% of all EPSS-scored CVEs.
- Exploitation confirmedCVE-2022-22965Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 99.9% of all EPSS-scored CVEs.
- Elevated exploitation riskCVE-2022-2297812.4% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 96% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2022-316923.6% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 89% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2024-222570.96% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 59% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-222280.59% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 46% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-227320.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-247340.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
Referenced CVEs
+1 more CVEs referenced in this advisory.
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [mittel] Netty: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Apache ActiveMQ: Mehrere Schwachstellencert-bund
- highexploited[UPDATE] [hoch] Apache Tomcat und Tomcat Native: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Apache Tomcat und Tomcat Native: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Kiali für Red Hat OpenShift Service Mesh (Axios, Go, Follow-redirects): Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Apache Tomcat: Mehrere Schwachstellencert-bund
- medium[UPDATE] [mittel] PostgreSQL JDBC Driver: Schwachstelle ermöglicht Denial of Servicecert-bund
- high[NEU] [hoch] IBM MQ Appliance (Axios Node.js): Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Red Hat Enterprise Linux (Apicurio Registry): Mehrere Schwachstellencert-bund
- highexploited[UPDATE] [hoch] IBM QRadar SIEM: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Oracle Fusion Middleware: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] Splunk SOAR: Mehrere Schwachstellencert-bund
Recent advisories for Atlassian Bamboo
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highexploited[UPDATE] [hoch] Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, und Jira): Mehrere Schwa…cert-bund · 2026-09-04
- high[UPDATE] [hoch] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: …cert-bund · 2026-09-04
- high[UPDATE] [high] Atlassian Bamboo, Bitbucket, Confluence, Jira: Multiple vulnerabilitiescert-bund · 2026-08-03
- high[UPDATE] [high] Atlassian products (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, and Jira): Multiple vuln…cert-bund · 2026-07-20
More from CERT-Bund (BSI) Security Advisories
- medium[NEU] [mittel] Microsoft Edge: Schwachstelle ermöglicht Cross-Site Scripting2026-09-14
- medium[NEU] [mittel] Citrix Systems Workspace App Windows: Mehrere Schwachstellen ermöglichen nicht spezifizierten A…2026-09-14
- medium[NEU] [mittel] wpa_supplicant: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen2026-09-14
- medium[NEU] [mittel] WP Royal Royal Elementor Addons: Schwachstelle ermöglicht Offenlegung von Informationen2026-09-14
- low[UPDATE] [niedrig] 7-Zip: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen2026-09-14