Atlassian

    Dashboard / Vendors

    Products: 60
    Vulnerabilities: 477
    Known Exploited: 13
    48
    Critical Level Threats
    123
    High Level Threats
    296
    Medium Level Threats
    4
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-21584

    Improper Authorization in Atlassian Bamboo Data Center Allowing Privilege Escalation

    Last Modified: Sep 02, 2026
    Published: Aug 18, 2026

    CVE-2026-21582

    Unauthenticated User Impersonation in Atlassian Crowd Data Center

    Last Modified: Aug 20, 2026
    Published: Aug 18, 2026

    CVE-2026-21580

    Stored XSS, Privilege Escalation, and Security Misconfiguration in Atlassian Confluence

    Last Modified: Aug 21, 2026
    Published: Aug 18, 2026

    CVE-2026-21575

    This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. Atlassian recommends that Sourcetree for Mac and Sourcetree for Windows customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: * Sourcetree for Mac and Sourcetree for Windows 3.4: Upgrade to a release greater than or equal to 3.4.13 See the release notes (https://www.sourcetreeapp.com/download-archives). You can download the latest version of Sourcetree for Mac and Sourcetree for Windows from the download center (https://www.sourcetreeapp.com/download-archives). This vulnerability was reported via our Bug Bounty program.

    Last Modified: Aug 12, 2026
    Published: Jul 21, 2026

    CVE-2026-21577

    This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a host connected to a network. Atlassian recommends that Confluence Data Center customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center 9.2: Upgrade to a release greater than or equal to 9.2.17 Confluence Data Center 10.2: Upgrade to a release greater than or equal to 10.2.7 See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center from the download center ([https://www.atlassian.com/software/confluence/download-archives]). This vulnerability was reported via our Penetration Testing program.

    Last Modified: Aug 04, 2026
    Published: Jul 21, 2026
    Items Per Page