Atlassian known exploited vulnerabilities
CISA lists 13 Atlassian CVEs as exploited in the wild. 0 were added in the last 12 months (latest 2024-11-12), and 8 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2021-26086 (Jira Server and Data Center): EPSS 100.0%, added 2024-11-12
- CVE-2023-22518 (Confluence Data Center and Server): EPSS 100.0%, added 2023-11-07
- CVE-2022-26134 (Confluence Server/Data Center): EPSS 100.0%, added 2022-06-02
- CVE-2021-26084 (Confluence Server and Data Center): EPSS 100.0%, added 2021-11-03
- CVE-2023-22527 (Confluence Data Center and Server): EPSS 100.0%, added 2024-01-24
Most affected Atlassian products
Confluence Data Center and Server (3), Jira Server and Data Center (2), Confluence Server and Data Center (2), Bitbucket Server and Data Center (1), Confluence (1), Confluence Server/Data Center (1), Confluence Server (1), Confluence Server and Data Server (1), Crowd and Crowd Data Center (1).
All Atlassian CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2021-26086 | Jira Server and Data Center | Jira Server and Data Center Path Traversal | 2024-11-12 | 2024-12-03 | 100.0% | – |
| CVE-2023-22527 | Confluence Data Center and Server | Confluence Data Center and Server Template Injection | 2024-01-24 | 2024-02-14 | 100.0% | Yes |
| CVE-2023-22518 | Confluence Data Center and Server | Confluence Data Center and Server Improper Authorization | 2023-11-07 | 2023-11-28 | 100.0% | Yes |
| CVE-2023-22515 | Confluence Data Center and Server | Confluence Data Center and Server Broken Access Control | 2023-10-05 | 2023-10-13 | 99.2% | Yes |
| CVE-2022-36804 | Bitbucket Server and Data Center | Bitbucket Server and Data Center Command Injection | 2022-09-30 | 2022-10-21 | 99.2% | – |
| CVE-2022-26138 | Confluence | Questions For Confluence App Hard-coded Credentials | 2022-07-29 | 2022-08-19 | 98.2% | – |
| CVE-2022-26134 | Confluence Server/Data Center | Confluence Server and Data Center Remote Code Execution | 2022-06-02 | 2022-06-06 | 100.0% | Yes |
| CVE-2021-26085 | Confluence Server | Confluence Server Pre-Authorization Arbitrary File Read | 2022-03-28 | 2022-04-18 | 99.9% | Yes |
| CVE-2019-11581 | Jira Server and Data Center | Jira Server and Data Center Server-Side Template Injection | 2022-03-07 | 2022-09-07 | 84.6% | – |
| CVE-2021-26084 | Confluence Server and Data Center | Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection | 2021-11-03 | 2021-11-17 | 100.0% | Yes |
| CVE-2019-3398 | Confluence Server and Data Center | Confluence Server and Data Center Path Traversal | 2021-11-03 | 2022-05-03 | 96.8% | – |
| CVE-2019-3396 | Confluence Server and Data Server | Confluence Server and Data Center Server-Side Template Injection | 2021-11-03 | 2022-05-03 | 99.9% | Yes |
| CVE-2019-11580 | Crowd and Crowd Data Center | Crowd and Crowd Data Center Remote Code Execution | 2021-11-03 | 2022-05-03 | 95.4% | Yes |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors