CyberMax
Home › Exploited CVEs

Atlassian known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 13 Atlassian CVEs as exploited in the wild. 0 were added in the last 12 months (latest 2024-11-12), and 8 are known to be used in ransomware campaigns.

Atlassian CVEs added to CISA KEV per year
2021: 4202142022: 5202252023: 2202322024: 220242

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected Atlassian products

Confluence Data Center and Server (3), Jira Server and Data Center (2), Confluence Server and Data Center (2), Bitbucket Server and Data Center (1), Confluence (1), Confluence Server/Data Center (1), Confluence Server (1), Confluence Server and Data Server (1), Crowd and Crowd Data Center (1).

All Atlassian CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2021-26086Jira Server and Data CenterJira Server and Data Center Path Traversal2024-11-122024-12-03100.0%–
CVE-2023-22527Confluence Data Center and ServerConfluence Data Center and Server Template Injection2024-01-242024-02-14100.0%Yes
CVE-2023-22518Confluence Data Center and ServerConfluence Data Center and Server Improper Authorization2023-11-072023-11-28100.0%Yes
CVE-2023-22515Confluence Data Center and ServerConfluence Data Center and Server Broken Access Control2023-10-052023-10-1399.2%Yes
CVE-2022-36804Bitbucket Server and Data CenterBitbucket Server and Data Center Command Injection2022-09-302022-10-2199.2%–
CVE-2022-26138ConfluenceQuestions For Confluence App Hard-coded Credentials2022-07-292022-08-1998.2%–
CVE-2022-26134Confluence Server/Data CenterConfluence Server and Data Center Remote Code Execution2022-06-022022-06-06100.0%Yes
CVE-2021-26085Confluence ServerConfluence Server Pre-Authorization Arbitrary File Read2022-03-282022-04-1899.9%Yes
CVE-2019-11581Jira Server and Data CenterJira Server and Data Center Server-Side Template Injection2022-03-072022-09-0784.6%–
CVE-2021-26084Confluence Server and Data CenterConfluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection2021-11-032021-11-17100.0%Yes
CVE-2019-3398Confluence Server and Data CenterConfluence Server and Data Center Path Traversal2021-11-032022-05-0396.8%–
CVE-2019-3396Confluence Server and Data ServerConfluence Server and Data Center Server-Side Template Injection2021-11-032022-05-0399.9%Yes
CVE-2019-11580Crowd and Crowd Data CenterCrowd and Crowd Data Center Remote Code Execution2021-11-032022-05-0395.4%Yes
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors