Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196331 vulns · 36/41 feeds (7d)
← Back to list
EST
PRE-CVE
atlassian

Multiple Critical Vulnerabilities in Atlassian Products

72% confidence

Description

Atlassian published a security advisory addressing multiple vulnerabilities, including critical ones, affecting several products including Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, Jira, Jira Service Management, and Sourcetree across Data Center, Server, and desktop versions.

Affected Products

VendorProductVersions
atlassian—Bamboo Data Center and Server – multiple versions, Bitbucket Data Center and Server – multiple versions, Confluence Data Center and Server – multiple versions, Crowd Data Center and Server – multiple versions, Fisheye/Crucible 4.9.0 to 4.9.11, Jira Data Center and Server – multiple versions, Jira Service Management Data Center and Server – multiple versions, Sourcetree for Mac 3.4.11 to 3.4.12, Sourcetree for Windows 3.4.11 to 3.4.12

Related News (1 articles)

Tier B
CCCS Canada32d ago
Atlassian security advisory (AV26-731)
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
PublishedJul 22, 2026
Last enriched32d ago
Tags
atlassianmultiple-productscriticaladvisory
Trending Score1
Source articles1
Independent1
Info Completeness4/14
Missing: cve_id, product, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-21582
CVE-2026-21582: This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduce
Trending: 20
NONECVE-2026-21580
CVE-2026-21580: This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was intro
Trending: 18
NONECVE-2026-21584
CVE-2026-21584: This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.
Trending: 13
NONECVE-2026-21579
CVE-2026-21579: This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1,
Trending: 2
NONECVE-2026-21577
CVE-2026-21577: This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9
Trending: 2

Pin to Dashboard

Verification

State: reported
Confidence: 72%

Vulnerability Timeline

CVE Published
Jul 22, 2026
Discovered by ZDM
Jul 22, 2026