Skip to content
Critical Vulnerabilities in Atlassian Products Expose Systems to Remote Attacks

Critical Vulnerabilities in Atlassian Products Expose Systems to Remote Attacks

First seen 18 Sep 2026, 16:55 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 18, 2026 at 18:54 UTC
  • CVE-2026-45674 allows man-in-the-middle attacks on Confluence.
  • Administrators must patch affected systems immediately to mitigate risks.
  • Multiple products, including Jira and Bamboo, are impacted by high-severity vulnerabilities.

Atlassian has released security patches addressing multiple vulnerabilities across its products, including Confluence, Jira, and Bamboo. Notably, CVE-2026-45674 poses a critical risk, allowing attackers to intercept connections via man-in-the-middle attacks. Other vulnerabilities, such as CVE-2026-54512 and CVE-2026-54513, enable remote code execution and system crashes. The vulnerabilities affect various versions of Atlassian's software, with administrators urged to apply patches immediately. The vulnerabilities were discovered through ongoing security assessments and a bug bounty program. Although no active exploitation has been confirmed, the severity of the vulnerabilities necessitates prompt action. The security bulletin lists a total of 144 high-severity and 17 critical-severity vulnerabilities that have been addressed.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2019-07-26
CVE-2019-13990 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2023-01-17
CVE-2022-41903 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-12
CVE-2026-45674 published
A critical vulnerability in Confluence allows man-in-the-middle attacks, with a CVSS score of 10.
Heise.De
2026-06-23
CVE-2026-54512 and CVE-2026-54513 published
Two high-severity vulnerabilities in Atlassian products enable remote code execution and system crashes.
Heise.De
2026-09-11
First public PoC for CVE-2026-45674
Proof-of-concept code for the critical vulnerability in Confluence was made public.
Heise.De
2026-09-16
Atlassian security bulletin released
Atlassian issued a security bulletin detailing 144 high-severity vulnerabilities fixed in recent updates.
Confluence.Atlassian
2026-09-18
Security patches urged for all affected systems
Atlassian emphasizes the importance of applying security patches to prevent potential exploitation.
Heise.De

More articles in this cluster (2)

Following this threat?

Track Atlassian and CVE-2019-13990 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed