[UPDATE] [hoch] Atlassian Bamboo, Bitbucket, Confluence, Jira: Mehrere Schwachstellen
Ein Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence und Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1229
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2021-03410.88% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 56% of all scored CVEs.
- Moderate exploitation riskCVE-2021-315972.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 79% of all scored CVEs.
- Exploitation likely imminentCVE-2022-1471EPSS puts this in the most-targeted tier (99.6% 30-day exploitation probability). Prioritize alongside KEV items. Riskier than 100% of all scored CVEs.
- Moderate exploitation riskCVE-2022-259271.7% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 75% of all scored CVEs.
- Moderate exploitation riskCVE-2023-13701.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 63% of all scored CVEs.
- Moderate exploitation riskCVE-2023-36351.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 67% of all scored CVEs.
- Moderate exploitation riskCVE-2023-486311.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 63% of all scored CVEs.
- Low exploitation riskCVE-2024-293710.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all scored CVEs.
- Low exploitation riskCVE-2024-458010.84% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 54% of all scored CVEs.
- Moderate exploitation riskCVE-2024-478751.1% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 62% of all scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[UPDATE] [medium] Apache Tomcat and Tomcat Native: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: Mul…cert-bund
- high[UPDATE] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: …cert-bund
- unknownApache Tomcat Multiple Vulnerabilitieshkcert
- high[UPDATE] [high] Apache Commons BeanUtils: Vulnerability allows bypassing security measurescert-bund
- high[NEW] [high] IBM Security Verify Access: Multiple vulnerabilitiescert-bund
- unknownMultiples vulnérabilités dans les produits IBM (31 juillet 2026)cert-fr-avis
- high[UPDATE] [high] Red Hat Ansible Automation Platform: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Oracle Communications: Multiple vulnerabilitiescert-bund
- high[UPDATE] [high] Apache Tomcat and Tomcat Native: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Atlassian products (July 27, 2026)cert-fr-avis
- unknownMultiple vulnerabilities in IBM products (July 24, 2026)cert-fr-avis
Recent advisories for Atlassian Bamboo
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: Mul…cert-bund · 2026-08-05
- high[UPDATE] [high] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira and Jira Service Management: …cert-bund · 2026-08-05
- high[UPDATE] [high] Atlassian products (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, and Jira): Multiple vuln…cert-bund · 2026-07-20
More from CERT-Bund (BSI) Security Advisories
- medium[NEU] [mittel] Linux Kernel: Mehrere Schwachstellen2026-08-05
- medium[NEU] [mittel] X.Org X11: Mehrere Schwachstellen ermöglichen Privilegieneskalation und Denial of Service2026-08-05
- medium[NEU] [mittel] Red Hat Ansible Automation Platform (ansible-core): Schwachstelle ermöglicht Codeausführung2026-08-05
- high[NEU] [hoch] Veeam ONE: Mehrere Schwachstellen2026-08-05
- medium[NEU] [mittel] Mozilla Firefox für Android: Schwachstelle ermöglicht Offenlegung von Informationen2026-08-05