Heise.De Critical Vulnerabilities in Atlassian Products Expose Systems to Remote Attacks
Article Content
- •CVE-2026-45674 allows man-in-the-middle attacks on Confluence.
- •Administrators must patch affected systems immediately to mitigate risks.
- •Multiple products, including Jira and Bamboo, are impacted by high-severity vulnerabilities.
Atlassian has released security patches addressing multiple vulnerabilities across its products, including Confluence, Jira, and Bamboo. Notably, CVE-2026-45674 poses a critical risk, allowing attackers to intercept connections via man-in-the-middle attacks. Other vulnerabilities, such as CVE-2026-54512 and CVE-2026-54513, enable remote code execution and system crashes. The vulnerabilities affect various versions of Atlassian's software, with administrators urged to apply patches immediately. The vulnerabilities were discovered through ongoing security assessments and a bug bounty program. Although no active exploitation has been confirmed, the severity of the vulnerabilities necessitates prompt action. The security bulletin lists a total of 144 high-severity and 17 critical-severity vulnerabilities that have been addressed.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Atlassian and CVE-2019-13990 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…