Security Bulletin - August 18 2026

Security Advisories & Bulletins

On this page

Still need help?

The Atlassian Community is here for you.

Ask the community

August 2026 Security Bulletin

The vulnerabilities reported in this Security Bulletin include 162 high-severity vulnerabilities and 10 critical-severity third-party vulnerabilities, which have been fixed in new versions of our products released in the last month.

CVEs reported in monthly Security Bulletins have been assessed as presenting a non-critical risk to Atlassian customers. Atlassian issues Critical Security Advisories for vulnerabilities that pose an immediate critical risk based on how our products actually use the affected components outside of our monthly Security Bulletin schedule as necessary.

Vulnerabilities are discovered through our Bug Bounty program, pen-testing processes, and third-party library scans.

INSTRUCTIONS

To fix all the vulnerabilities impacting your product(s), Atlassian recommends patching your instances to the latest version or one of the Fixed Versions for each product below. The listed Fixed Versions for each product are current as of August 18, 2026 (date of publication); visit the linked product Release Notes for the most up-to-date versions.

To search for CVEs or check your product versions for disclosed vulnerabilities, check the Vulnerability Disclosure Portal.

Released Security Vulnerabilities
Product & Release NotesAffected VersionsFixed VersionVulnerability SummaryCVE IDCVSS Severity
Bamboo Data Center and Server
  • 12.1.0 to 12.1.9 (LTS)
  • 12.0.0 to 12.0.2
  • 11.0.0 to 11.0.8
  • 10.2.0 to 10.2.21 (LTS)
  • 10.1.0 to 10.1.1
  • 10.0.0 to 10.0.3
  • 12.1.10 (LTS) recommended Data Center Only
  • 10.2.22 (LTS) Data Center Only
RCE (Remote Code Execution) org.bouncycastle:bcprov-jdk18on Dependency in Bamboo Data CenterCVE-2026-146828.7 High
RCE (Remote Code Execution) form-data Dependency in Bamboo Data CenterCVE-2026-121438.7 High
DoS (Denial of Service) org.bouncycastle:bcprov-jdk18on Dependency in Bamboo Data CenterCVE-2026-580598.7 High
Cryptographic Failure org.bouncycastle:bcpkix-jdk18on Dependency in Bamboo Data CenterCVE-2026-128028.7 High
RCE (Remote Code Execution) org.bouncycastle:bcprov-jdk18on Dependency in Bamboo Data CenterCVE-2026-580608.7 High
Cryptographic Failure org.bouncycastle:bcprov-jdk18on Dependency in Bamboo Data CenterCVE-2026-128038.7 High
DoS (Denial of Service) org.bouncycastle:bcprov-jdk18on Dependency in Bamboo Data CenterCVE-2026-135068.7 High
DoS (Denial of Service) io.netty:netty-codec-http Dependency in Bamboo Data CenterCVE-2026-567458.7 High
Cryptographic Failure org.bouncycastle:bcpkix-jdk18on Dependency in Bamboo Data CenterCVE-2026-596398.7 High
Cryptographic Failure org.bouncycastle:bcprov-jdk18on Dependency in Bamboo Data CenterCVE-2026-128168.7 High
DoS (Denial of Service) io.netty:netty-codec Dependency in Bamboo Data CenterCVE-2026-599018.7 High
Cryptographic Failure org.bouncycastle:bcpkix-jdk18on Dependency in Bamboo Data CenterCVE-2026-596428.7 High
SQLi (SQL Injection) org.hibernate:hibernate-core-jakarta Dependency in Bamboo Data CenterCVE-2026-06038.3 High
Information Disclosure axios Dependency in Bamboo Data CenterCVE-2026-673208.3 High
MITM (Man-in-the-Middle) org.postgresql:postgresql Dependency in Bamboo Data CenterCVE-2026-542918.2 High
RCE (Remote Code Execution) uuid Dependency in Bamboo Data CenterCVE-2026-419078.1 High
DoS (Denial of Service) org.springframework:spring-expression Dependency in Bamboo Data CenterCVE-2026-418517.5 High
DoS (Denial of Service) io.netty:netty-codec-http Dependency in Bamboo Data CenterCVE-2026-558317.5 High
DoS (Denial of Service) org.springframework:spring-expression Dependency in Bamboo Data CenterCVE-2026-418507.5 High
DoS (Denial of Service) io.netty:netty-codec-http Dependency in Bamboo Data CenterCVE-2026-558337.5 High
DoS (Denial of Service) org.springframework:spring-webmvc Dependency in Bamboo Data CenterCVE-2026-418427.5 High
Injection js-cookie Dependency in Bamboo Data CenterCVE-2026-466257.5 High
Injection fast-uri Dependency in Bamboo Data CenterCVE-2026-63227.5 High
File Inclusion fast-uri Dependency in Bamboo Data CenterCVE-2026-63217.5 High
Injection fast-uri Dependency in Bamboo Data CenterCVE-2026-136767.5 High
Injection fast-uri Dependency in Bamboo Data CenterCVE-2026-162217.5 High
DoS (Denial of Service) io.netty:netty-codec-http2 Dependency in Bamboo Data CenterCVE-2026-568197.5 High
Injection fast-uri Dependency in Bamboo Data CenterCVE-2026-184467.5 High
DoS (Denial of Service) io.micrometer:micrometer-core Dependency in Bamboo Data CenterCVE-2026-409837.5 High
DoS (Denial of Service) io.micrometer:micrometer-core Dependency in Bamboo Data CenterCVE-2026-409847.5 High
Bitbucket Data Center and Server
  • 10.4.1
  • 10.3.0 to 10.3.2
  • 10.2.0 to 10.2.5 (LTS)
  • 10.1.1 to 10.1.5
  • 10.0.0 to 10.0.2
  • 9.6.0 to 9.6.5
  • 9.5.0 to 9.5.2
  • 9.4.0 to 9.4.22 (LTS)
  • 9.3.0 to 9.3.2
  • 9.2.0 to 9.2.1
  • 9.1.0 to 9.1.1
  • 10.4.2 Data Center Only
  • 10.2.6 (LTS) recommended Data Center Only
  • 9.4.23 (LTS) Data Center Only
DoS (Denial of Service) org.bouncycastle:bcpg-lts8on Dependency in Bitbucket Data CenterCVE-2026-35058.7 High
RCE (Remote Code Execution) form-data Dependency in Bitbucket Data CenterCVE-2026-121438.7 High
Information Disclosure axios Dependency in Bitbucket Data CenterCVE-2026-673208.3 High
MITM (Man-in-the-Middle) org.postgresql:postgresql Dependency in Bitbucket Data CenterCVE-2026-542918.2 High
DoS (Denial of Service) brace-expansion Dependency in Bitbucket Data CenterCVE-2026-131497.7 High
Injection fast-uri Dependency in Bitbucket Data CenterCVE-2026-184467.5 High
DoS (Denial of Service) js-yaml Dependency in Bitbucket Data CenterCVE-2026-598697.5 High
DoS (Denial of Service) io.netty:netty-codec-http2 Dependency in Bitbucket Data CenterCVE-2026-568197.5 High
DoS (Denial of Service) brace-expansion Dependency in Bitbucket Data CenterCVE-2026-691527.5 High
Injection fast-uri Dependency in Bitbucket Data CenterCVE-2026-162217.5 High
Injection fast-uri Dependency in Bitbucket Data CenterCVE-2026-136767.5 High
DoS (Denial of Service) ws Dependency in Bitbucket Data CenterCVE-2026-487797.5 High
DoS (Denial of Service) io.micrometer:micrometer-core Dependency in Bitbucket Data CenterCVE-2026-409837.5 High
DoS (Denial of Service) brace-expansion Dependency in Bitbucket Data CenterCVE-2026-142577.5 High
DoS (Denial of Service) minimatch Dependency in Bitbucket Data CenterCVE-2022-35177.5 High
Confluence Data Center and Server
  • 10.2.0 to 10.2.14 (LTS)
  • 10.1.0 to 10.1.2
  • 10.0.2 to 10.0.3
  • 9.5.1 to 9.5.4
  • 9.4.0 to 9.4.1
  • 9.3.1 to 9.3.2
  • 9.2.0 to 9.2.22 (LTS)
  • 9.1.0 to 9.1.1
  • 9.0.3
  • 8.9.6 to 8.9.8
  • 8.5.15 to 8.5.31 (LTS)
  • 7.19.27 to 7.19.30 (LTS)
  • 10.2.15 (LTS) recommended Data Center Only
  • 9.2.23 (LTS) Data Center Only
Injection minimist Dependency in Confluence Data CenterCVE-2021-44906

9.8 Critical

This is a vulnerability in a non-Atlassian Confluence dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

Security Misconfiguration org.bouncycastle:bcprov-lts8on Dependency in Confluence Data CenterCVE-2025-14813

9.3 Critical

This is a vulnerability in a non-Atlassian Confluence dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

DoS (Denial of Service) tar Dependency in Confluence Data CenterCVE-2026-59873

9.2 Critical

This is a vulnerability in a non-Atlassian Confluence dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

MITM (Man-in-the-Middle) org.apache.tomcat:tomcat-coyote-ffm Dependency in Confluence Data CenterCVE-2026-53434

9.1 Critical

This is a vulnerability in a non-Atlassian Confluence dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

DoS (Denial of Service) linkify-it Dependency in Confluence Data CenterCVE-2026-488018.7 High
Denial of Service (DoS) tar Dependency in Confluence Data CenterCVE-2026-598748.7 High
SQLi (SQL Injection) org.hibernate:hibernate-core Dependency in Confluence Data CenterCVE-2026-06038.3 High
File Inclusion tar Dependency in Confluence Data CenterCVE-2026-297868.2 High
MITM (Man-in-the-Middle) org.postgresql:postgresql Dependency in Confluence Data CenterCVE-2026-542918.2 High
DoS (Denial of Service) underscore Dependency in Confluence Data CenterCVE-2026-276018.2 High
DoS (Denial of Service) tar Dependency in Confluence Data CenterCVE-2026-598717.5 High
DoS (Denial of Service) linkify-it Dependency in Confluence Data CenterCVE-2026-598877.5 High
DoS (Denial of Service) org.postgresql:postgresql Dependency in Confluence Data CenterCVE-2026-421987.5 High
Information Disclosure postcss Dependency in Confluence Data CenterCVE-2026-456237.5 High
DoS (Denial of Service) io.micrometer:micrometer-core Dependency in Confluence Data CenterCVE-2026-409837.5 High
DoS (Denial of Service) axios Dependency in Confluence Data CenterCVE-2026-256397.5 High
Crowd Data Center and Server
  • 7.2.0 to 7.2.1
  • 7.1.0 to 7.1.5
  • 7.0.0 to 7.0.2
  • 6.3.0 to 6.3.6
  • 6.2.0 to 6.2.6
  • 6.1.0 to 6.1.7
  • 6.0.2 to 6.0.10
  • 7.2.2 to 7.2.3 recommended Data Center Only
BASM (Broken Authentication & Session Management) in Crowd Data CenterCVE-2026-215828.8 High
DoS (Denial of Service) io.netty:netty-codec-http Dependency in Crowd Data CenterCVE-2026-567458.7 High
Injection axios Dependency in Crowd Data CenterCVE-2026-444948.7 High
DoS (Denial of Service) io.netty:netty-codec Dependency in Crowd Data CenterCVE-2026-599018.7 High
SSRF (Server-Side Request Forgery) axios Dependency in Crowd Data CenterCVE-2026-444928.6 High
Information Disclosure axios Dependency in Crowd Data CenterCVE-2026-673208.3 High
SQLi (SQL Injection) org.hibernate:hibernate-core-jakarta Dependency in Crowd Data CenterCVE-2026-06038.3 High
Information Disclosure axios Dependency in Crowd Data CenterCVE-2026-444878.2 High
Injection axios Dependency in Crowd Data CenterCVE-2026-420418.2 High
Injection axios Dependency in Crowd Data CenterCVE-2026-444908.2 High
MITM (Man-in-the-Middle) org.postgresql:postgresql Dependency in Crowd Data CenterCVE-2026-542918.2 High
DoS (Denial of Service) underscore Dependency in Crowd Data CenterCVE-2026-276018.2 High
Insecure Deserialization jackson-databind Dependency in Crowd Data CenterCVE-2026-545138.1 High
Insecure Deserialization jackson-databind in Crowd Data CenterCVE-2026-545128.1 High
Improper Authorization io.netty:netty-handler Dependency in Crowd Data CenterCVE-2026-442498.1 High
BASM (Broken Authentication & Session Management) org.springframework.security:spring-security-web Dependency in Crowd Data CenterCVE-2026-478388.1 High
DoS (Denial of Service) io.netty:netty-handler Dependency in Crowd Data CenterCVE-2026-454167.5 High
DoS (Denial of Service) org.apache.tomcat:tomcat-catalina Dependency in Crowd Data CenterCVE-2026-412847.5 High
DoS (Denial of Service) org.springframework:spring-webmvc Dependency in Crowd Data CenterCVE-2026-418427.5 High
MITM (Man-in-the-Middle) io.netty:netty-handler Dependency in Crowd Data CenterCVE-2026-500107.5 High
DoS (Denial of Service) axios Dependency in Crowd Data CenterCVE-2026-444967.5 High
Information Disclosure axios Dependency in Crowd Data CenterCVE-2026-444867.5 High
DoS (Denial of Service) axios Dependency in Crowd Data CenterCVE-2026-444887.5 High
DoS (Denial of Service) io.netty:netty-codec-http Dependency in Crowd Data CenterCVE-2026-558317.5 High
DoS (Denial of Service) io.micrometer:micrometer-core Dependency in Crowd Data CenterCVE-2026-409837.5 High
DoS (Denial of Service) io.netty:netty-codec-http Dependency in Crowd Data CenterCVE-2026-558337.5 High
Information Disclosure postcss Dependency in Crowd Data CenterCVE-2026-456237.5 High
DoS (Denial of Service) io.netty:netty-codec-http2 Dependency in Crowd Data CenterCVE-2026-480437.5 High
Business Logic Vulnerability org.apache.tomcat:tomcat-catalina Dependency in Crowd Data CenterCVE-2026-435137.5 High
Injection js-cookie Dependency in Crowd Data CenterCVE-2026-466257.5 High
DoS (Denial of Service) io.micrometer:micrometer-core Dependency in Crowd Data CenterCVE-2026-409847.5 High
DoS (Denial of Service) org.springframework:spring-expression Dependency in Crowd Data CenterCVE-2026-418517.5 High
DoS (Denial of Service) org.springframework:spring-expression Dependency in Crowd Data CenterCVE-2026-418507.5 High
DoS (Denial of Service) io.netty:netty-codec-http2 Dependency in Crowd Data CenterCVE-2026-568197.5 High
Injection axios Dependency in Crowd Data CenterCVE-2026-420357.4 High
Injection axios Dependency in Crowd Data CenterCVE-2026-420337.4 High
DOM-based XSS org.springframework:spring-webmvc Dependency in Crowd Data CenterCVE-2026-418457.1 High
RCE (Remote Code Execution) axios Dependency in Crowd Data CenterCVE-2026-444957 High
Fisheye/Crucible
  • 4.9.0 to 4.9.12
  • 4.9.13 recommended
Inconsistent Interpretation of HTTP Requests at org.eclipse.jetty:jetty-http dependency in Crucible ServerCVE-2026-2332

9.1 Critical

This is a vulnerability in a non-Atlassian Fisheye/Crucible dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

BASM (Broken Authentication & Session Management) org.eclipse.jetty:jetty-security Dependency in Crucible ServerCVE-2026-100508.7 High
MITM (Man-in-the-Middle) org.postgresql:postgresql Dependency in Crucible Data Center and ServerCVE-2026-542918.2 High
DoS (Denial of Service) com.fasterxml.jackson.core:jackson-databind Dependency in Crucible ServerCVE-2026-545128.1 High
Injection com.fasterxml.jackson.core:jackson-databind Dependency in Crucible ServerCVE-2026-545138.1 High
Jira Data Center and Server
  • 11.3.0 to 11.3.8 (LTS)
  • 11.2.0 to 11.2.1
  • 11.1.0 to 11.1.1
  • 11.0.0 to 11.0.1
  • 10.7.1 to 10.7.4
  • 10.6.0 to 10.6.1
  • 10.5.0 to 10.5.1
  • 10.4.0 to 10.4.1
  • 10.3.0 to 10.3.23 (LTS)
  • 10.2.0 to 10.2.1
  • 10.1.1 to 10.1.2
  • 10.0.0 to 10.0.1
  • 9.17.3 to 9.17.5
  • 9.12.13 to 9.12.37 (LTS)
  • 11.3.10 (LTS) recommended Data Center Only
  • 10.3.24 (LTS) recommended Data Center Only
RCE (Remote Code Execution) at lodash dependency in Jira Software Data CenterCVE-2026-4800

9.8 Critical

This is a vulnerability in a non-Atlassian Jira Data Center dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

Arbitrary code execution (RCE) @babel/traverse dependency in Jira Software Data CenterCVE-2023-45133

9.3 Critical

This is a vulnerability in a non-Atlassian Jira Data Center dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

DoS (Denial of Service) node-tar dependency in Jira Software Data CenterCVE-2026-59873

9.2 Critical

This is a vulnerability in a non-Atlassian Jira Data Center dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

BASM (Broken Authentication & Session Management) in Jira Data CenterCVE-2026-215828.8 High
File Inclusion rollup Dependency in Jira Software Data CenterCVE-2026-276068.8 High
Injection axios Dependency in Jira Software Data CenterCVE-2026-444948.7 High
DoS (Denial of Service) io.netty:netty-codec Dependency in Jira Software Data CenterCVE-2026-599018.7 High
DoS (Denial of Service) react-router Dependency in Jira Software Data CenterCVE-2026-556858.7 High
RCE (Remote Code Execution) form-data Dependency in Jira Software Data CenterCVE-2026-121438.7 High
DoS (Denial of Service) io.netty:netty-codec-http Dependency in Jira Software Data CenterCVE-2026-567458.7 High
DoS (Denial of Service) tar Dependency in Jira Software Data CenterCVE-2026-598748.7 High
SSRF (Server-Side Request Forgery) axios Dependency in Jira Software Data CenterCVE-2026-444928.6 High
MITM (Man-in-the-Middle) org.postgresql:postgresql Dependency in Jira Software Data CenterCVE-2026-542918.2 High
Information Disclosure axios Dependency in Jira Software Data CenterCVE-2026-444878.2 High
Improper Authorization io.netty:netty-handler Dependency in Jira Software Data CenterCVE-2026-442498.1 High
BASM (Broken Authentication & Session Management) org.springframework.security:spring-security-web Dependency in Jira Software Data CenterCVE-2026-478388.1 High
SSRF (Server-Side Request Forgery) ip-address Dependency in Jira Software Data CenterCVE-2026-691927.7 High
DoS (Denial of Service) brace-expansion Dependency in Jira Software Data CenterCVE-2026-131497.7 High
Injection js-cookie Dependency in Jira Software Data CenterCVE-2026-466257.5 High
MITM (Man-in-the-Middle) io.netty:netty-handler Dependency in Jira Software Data CenterCVE-2026-500107.5 High
DoS (Denial of Service) io.netty:netty-codec-http Dependency in Jira Software Data CenterCVE-2026-558337.5 High
DoS (Denial of Service) io.netty:netty-codec-http2 Dependency in Jira Software Data CenterCVE-2026-568197.5 High
DoS (Denial of Service) io.netty:netty-handler Dependency in Jira Software Data CenterCVE-2026-454167.5 High
DoS (Denial of Service) io.netty:netty-codec-http2 Dependency in Jira Software Data CenterCVE-2026-480437.5 High
DoS (Denial of Service) io.netty:netty-codec Dependency in Jira Software Data CenterCVE-2026-425877.5 High
DoS (Denial of Service) tar Dependency in Jira Software Data CenterCVE-2026-598717.5 High
DoS (Denial of Service) undici Dependency in Jira Software Data CenterCVE-2026-121517.5 High
Injection org.apache.tomcat:tomcat-coyote-ffm Dependency in Jira Software Data CenterCVE-2026-247347.5 High
DoS (Denial of Service) org.springframework:spring-webmvc Dependency in Jira Software Data CenterCVE-2026-418427.5 High
DoS (Denial of Service) axios Dependency in Jira Software Data CenterCVE-2026-444887.5 High
Information Disclosure axios Dependency in Jira Software Data CenterCVE-2026-444867.5 High
DoS (Denial of Service) io.netty:netty-codec-http Dependency in Jira Software Data CenterCVE-2026-558317.5 High
DoS (Denial of Service) io.netty:netty-codec Dependency in Jira Software Data CenterCVE-2026-425837.5 High
DoS (Denial of Service) io.micrometer:micrometer-core Dependency in Jira Software Data CenterCVE-2026-409837.5 High
DOM-based XSS org.springframework:spring-webmvc Dependency in Jira Software Data CenterCVE-2026-418457.1 High
Jira Service Management Data Center and Server
  • 11.3.0 to 11.3.8 (LTS)
  • 11.2.0 to 11.2.1
  • 11.1.0 to 11.1.1
  • 11.0.0 to 11.0.1
  • 10.7.1 to 10.7.4
  • 10.6.0 to 10.6.1
  • 10.5.0 to 10.5.1
  • 10.4.0 to 10.4.1
  • 10.3.0 to 10.3.23 (LTS)
  • 10.2.0 to 10.2.1
  • 10.1.1 to 10.1.2
  • 10.0.0 to 10.0.1
  • 5.17.3 to 5.17.5
  • 11.3.10 (LTS) recommended Data Center Only
  • 10.3.24 (LTS) Data Center Only
RCE (Remote Code Execution) in Jira Service Management Data CenterCVE-2026-4800

9.8 Critical

This is a vulnerability in a non-Atlassian Jira Service Management dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

DoS (Denial of Service) tar Dependency in Jira Service Management Data CenterCVE-2026-59873

9.2 Critical

This is a vulnerability in a non-Atlassian Jira Service Management dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

BASM (Broken Authentication & Session Management) in Jira Service Management Data CenterCVE-2026-215828.8 High
File Inclusion rollup Dependency in Jira Service Management Data CenterCVE-2026-276068.8 High
DoS (Denial of Service) tar Dependency in Jira Service Management Data CenterCVE-2026-598748.7 High
DoS (Denial of Service) io.netty:netty-codec Dependency in Jira Service Management Data CenterCVE-2026-599018.7 High
Injection axios Dependency in Jira Service Management Data CenterCVE-2026-444948.7 High
DoS (Denial of Service) react-router Dependency in Jira Service Management Data CenterCVE-2026-556858.7 High
DoS (Denial of Service) io.netty:netty-codec-http Dependency in Jira Service Management Data CenterCVE-2026-567458.7 High
RCE (Remote Code Execution) form-data Dependency in Jira Service Management Data CenterCVE-2026-121438.7 High
SSRF (Server-Side Request Forgery) axios Dependency in Jira Service Management Data CenterCVE-2026-444928.6 High
Injection axios Dependency in Jira Service Management Data CenterCVE-2026-444908.2 High
Information Disclosure axios Dependency in Jira Service Management Data CenterCVE-2026-444878.2 High
MITM (Man-in-the-Middle) org.postgresql:postgresql Dependency in Jira Service Management Data CenterCVE-2026-542918.2 High
Improper Authorization io.netty:netty-handler Dependency in Jira Service Management Data CenterCVE-2026-442498.1 High
DoS (Denial of Service) brace-expansion Dependency in Jira Service Management Data CenterCVE-2026-131497.7 High
SSRF (Server-Side Request Forgery) ip-address Dependency in Jira Service Management Data CenterCVE-2026-691927.7 High
Injection js-cookie Dependency in Jira Service Management Data CenterCVE-2026-466257.5 High
DoS (Denial of Service) io.netty:netty-codec-http2 Dependency in Jira Service Management Data CenterCVE-2026-568197.5 High
DoS (Denial of Service) tar Dependency in Jira Service Management Data CenterCVE-2026-598717.5 High
DoS (Denial of Service) io.netty:netty-codec-http Dependency in Jira Service Management Data CenterCVE-2026-558317.5 High
DoS (Denial of Service) axios Dependency in Jira Service Management Data CenterCVE-2026-444887.5 High
DoS (Denial of Service) io.netty:netty-handler Dependency in Jira Service Management Data CenterCVE-2026-454167.5 High
DoS (Denial of Service) undici Dependency in Jira Service Management Data CenterCVE-2026-121517.5 High
DoS (Denial of Service) io.netty:netty-codec-http Dependency in Jira Service Management Data CenterCVE-2026-558337.5 High
DoS (Denial of Service) io.netty:netty-codec-http2 Dependency in Jira Service Management Data CenterCVE-2026-480437.5 High
MITM (Man-in-the-Middle) io.netty:netty-handler Dependency in Jira Service Management Data Center and ServerCVE-2026-500107.5 High
DoS (Denial of Service) io.micrometer:micrometer-core Dependency in Jira Service Management Data CenterCVE-2026-409837.5 High
Injection org.apache.tomcat:tomcat-coyote-ffm Dependency in Jira Service Management Data CenterCVE-2026-247347.5 High
DoS (Denial of Service) axios Dependency in Jira Service Management Data CenterCVE-2026-444967.5 High
Information Disclosure axios Dependency in Jira Service Management Data CenterCVE-2026-444867.5 High
DoS (Denial of Service) org.springframework:spring-webmvc Dependency in Jira Service Management Data CenterCVE-2026-418427.5 High
DOM-based XSS org.springframework:spring-webmvc Dependency in Jira Service Management Data CenterCVE-2026-418457.1 High


Frequently Asked Questions:

  • Why is my Feature Version not listed in a Fixed Version? You may be using an unsupported version and need to patch to the latest version or Long-Term Support (LTS) version.

  • What are the most up-to-date Data Center product versions? You can always check the software download portal or visit the product-specific download pages.
  • I am using an LTS, why is it not listed in the Fixed Versions? Your LTS version may not have been updated yet or a backported fix may not have been feasible. Please see our Security Bug Fix Policy for more information. We recommend upgrading your products to the latest versions. For the latest fixed versions, visit the release notes linked in the vulnerability table.

  • Questions about the bulletin, have feedback? Let us know! Read more about our bulletins and feel free to contribute feedback on our latest Community Post


To search for CVEs or check your products versions for disclosed vulnerabilities, check the Vulnerability Disclosure Portal.

Last modified on Aug 19, 2026

Was this helpful?

Yes
No
Provide feedback about this article
Powered by Confluence and Scroll Viewport.