Attackers can target multiple Atlassian applications and, in the worst case, gain full access to systems. Security patches have now been released.
The developers list all vulnerable applications in the security section of the Atlassian website . These include Bamboo, Confluence, and Jira Service Management, among others. In many cases, malicious code can enter systems or crashes can occur.
For example, attackers can crash Bamboo (CVE-2026-54512 “ high ”) or execute malicious code remotely (CVE-2026-54513 “ high ”). Confluence is threatened by a “ critical ” vulnerability (CVE-2026-45674) with a maximum CVSS score of 10 out of 10. In this case, an attacker can intercept connections as a man-in-the-middle.
Even though the software manufacturer has not indicated any ongoing attacks, administrators should not delay installing the security patches. According to the developers, these versions are fixed:
Bamboo Data Center and Server 12.1.11 (LTS) recommended Data Center Only, 10.2.23 (LTS) Data Center Only
Bitbucket Data Center and Server 10.4.2 to 10.4.3 Data Center Only, 10.2.6 to 10.2.7 (LTS) recommended Data Center Only, 9.4.24 (LTS) Data Center Only
Confluence Data Center and Server 10.2.17 to 10.2.18 (LTS) recommended Data Center Only, 9.2.24 to 9.2.25 (LTS) Data Center Only
Crowd Data Center and Server 7.2.3 recommended Data Center Only
Fisheye/Crucible 4.9.14 recommended
Jira Data Center and Server 11.3.11 (LTS) recommended Data Center Only, 10.3.25 (LTS) Data Center Only
Jira Service Management Data Center and Server 11.3.11 (LTS) recommended Data Center Only, 10.3.25 (LTS) Data Center Only
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
