Security Bulletin - July 21 2026

Security Advisories & Bulletins

On this page

Still need help?

The Atlassian Community is here for you.

Ask the community

July 2026 Security Bulletin

The vulnerabilities reported in this Security Bulletin include 83 high-severity vulnerabilities and 18 critical-severity third-party vulnerabilities, which have been fixed in new versions of our products released in the last month.

CVEs reported in monthly Security Bulletins have been assessed as presenting a non-critical risk to Atlassian customers. Atlassian issues Critical Security Advisories for vulnerabilities that pose an immediate critical risk based on how our products actually use the affected components outside of our monthly Security Bulletin schedule as necessary.

Vulnerabilities are discovered through our Bug Bounty program, pen-testing processes, and third-party library scans.

The increase in reported vulnerabilities this month is attributed to externally coordinated security research and patching activity across several widely-used open-source libraries. These upstream events are reflected in our dependency scanning results and do not indicate a change in Atlassian's own security posture.

INSTRUCTIONS

To fix all the vulnerabilities impacting your product(s), Atlassian recommends patching your instances to the latest version or one of the Fixed Versions for each product below. The listed Fixed Versions for each product are current as of July 21, 2026 (date of publication); visit the linked product Release Notes for the most up-to-date versions.

To search for CVEs or check your product versions for disclosed vulnerabilities, check the Vulnerability Disclosure Portal.

Released Security Vulnerabilities

Product & Release Notes

Affected Versions

Fixed Version

Vulnerability Summary

CVE ID

CVSS Severity

Bamboo Data Center and Server

  • 12.1.0 to 12.1.8 (LTS)

  • 12.0.0 to 12.0.2

  • 11.0.0 to 11.0.8

  • 10.2.0 to 10.2.20 (LTS)

  • 10.1.0 to 10.1.1

  • 10.0.0 to 10.0.3

  • 12.1.9 (LTS) recommended Data Center Only

  • 10.2.21 (LTS) Data Center Only

RCE (Remote Code Execution) at lodash dependency in Bamboo Data Center

CVE-2026-4800

9.8 Critical

This is a vulnerability in a non-Atlassian Bamboo dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

RCE (Remote Code Execution) at Apache ActiveMQ dependency in Bamboo Data Center

CVE-2026-45505

8.8 High

Injection at axios dependency in Bamboo Data Center

CVE-2026-44494

8.7 High

Injection at axios dependency in Bamboo Data Center

CVE-2026-44490

8.2 High

RCE (Remote Code Execution) at Apache ActiveMQ dependency in Bamboo Data Center

CVE-2026-42588

8.1 High

Improper Authorization netty Dependency in Bamboo Data Center

CVE-2026-44249

8.1 High

Information Disclosure at Apache Tomcat dependency in Bamboo Data Center

CVE-2026-29146

7.5 High

DoS (Denial of Service) at netty-handler Dependency in Bamboo Data Center

CVE-2026-45416

7.5 High

Improper Verification of Cryptographic Signature at netty-handler dependency in Bamboo Data Center

CVE-2026-50010

7.5 High

RCE (Remote Code Execution) at axios dependency in Bamboo Data Center

CVE-2026-44495

7 High

Bitbucket Data Center and Server

  • 10.3.0 to 10.3.1

  • 10.2.0 to 10.2.5 (LTS)

  • 10.1.1 to 10.1.5

  • 10.0.0 to 10.0.2

  • 9.6.0 to 9.6.5

  • 9.5.0 to 9.5.2

  • 9.4.0 to 9.4.21 (LTS)

  • 9.3.0 to 9.3.2

  • 9.2.0 to 9.2.1

  • 9.1.0 to 9.1.1

  • 9.0.1

  • 10.3.2 Data Center Only

  • 10.2.5 (LTS) recommended Data Center Only

  • 9.4.22 (LTS) Data Center Only

RCE (Remote Code Execution) at 'getobject' version in Bitbucket Data Center

CVE-2020-28282

9.8 Critical

This is a vulnerability in a non-Atlassian Bitbucket dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

Cryptographic Failure org.bouncycastle:bcprov-jdk18on Dependency in Bitbucket Data Center

CVE-2026-5598

8.9 High

DoS (Denial of Service) with Netty Dependency in Bitbucket Data Center

CVE-2026-33871

8.7 High

Injection in Bitbucket Data Center

CVE-2026-44494

8.7 High

Race condition in Bitbucket Data Center

CVE-2026-35554

8.7 High

SSRF (Server-Side Request Forgery) in Bitbucket Data Center

CVE-2026-44492

8.6 High

Injection axios Dependency in Bitbucket Data Center

CVE-2026-42041

8.2 High

Injection in Bitbucket Data Center

CVE-2026-44490

8.2 High

BASM (Broken Authentication & Session Management) org.springframework.boot:spring-boot-actuator-autoconfigure Dependency in Bitbucket Data Center

CVE-2026-22731

8.2 High

Information Disclosure in Bitbucket Data Center

CVE-2026-44487

8.2 High

BASM (Broken Authentication & Session Management) in Bitbucket Data Center

CVE-2026-47838

8.1 High

HTTP Request Smuggling io.netty:netty-codec-http Dependency in Bitbucket Data Center

CVE-2026-33870

7.5 High

Injection in Bitbucket Data Center

CVE-2026-6322

7.5 High

File Inclusion in Bitbucket Data Center

CVE-2026-6321

7.5 High

DoS (Denial of Service) in Bitbucket Data Center

CVE-2026-44488

7.5 High

HTTP Request Smuggling io.netty:netty-codec-http Dependency in Bitbucket Data Center

CVE-2026-42585

7.5 High

DoS (Denial of Service) in Bitbucket Data Center

CVE-2026-44496

7.5 High

RCE (Remote Code Execution) in Bitbucket Data Center

CVE-2026-45736

7.5 High

Injection in Bitbucket Data Center

CVE-2026-46625

7.5 High

DoS (Denial of Service) in Bitbucket Data Center

CVE-2016-10540

7.5 High

DoS (Denial of Service) in Bitbucket Data Center

CVE-2026-48043

7.5 High

Information Disclosure in Bitbucket Data Center

CVE-2026-44486

7.5 High

RCE (Remote Code Execution) in Bitbucket Data Center

CVE-2021-23358

7.2 High

RCE (Remote Code Execution) grunt Dependency in Bitbucket Data Center

CVE-2020-7729

7.1 High

RCE (Remote Code Execution) in Bitbucket Data Center

CVE-2026-44495

7 High

Race condition in Bitbucket Data Center

CVE-2022-1537

7 High

Confluence Data Center and Server

  • 10.2.0 to 10.2.13 (LTS)

  • 10.1.0 to 10.1.2

  • 10.0.2 to 10.0.3

  • 9.5.1 to 9.5.4

  • 9.4.0 to 9.4.1

  • 9.3.1 to 9.3.2

  • 9.2.0 to 9.2.21 (LTS)

  • 9.1.0 to 9.1.1

  • 9.0.1 to 9.0.3

  • 8.9.5 to 8.9.8

  • 8.5.14 to 8.5.31 (LTS)

  • 7.19.26 to 7.19.30 (LTS)

  • 10.2.14 (LTS) recommended Data Center Only

  • 9.2.22 (LTS) Data Center Only

SSRF (Server-Side Request Forgery) axios Dependency in Confluence Data Center

CVE-2026-42043

10 Critical

This is a vulnerability in a non-Atlassian Confluence dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

SSRF (Server-Side Request Forgery) axios Dependency in Confluence Data Center

CVE-2025-62718

9.9 Critical

This is a vulnerability in a non-Atlassian Confluence dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

RCE (Remote Code Execution) at lodash dependency in Confluence Data Center

CVE-2026-4800

9.8 Critical

This is a vulnerability in a non-Atlassian Confluence dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

HTTP Request Smuggling org.eclipse.jetty:jetty-http Dependency in Confluence Data Center

CVE-2026-2332

9.1 Critical

This is a vulnerability in a non-Atlassian Confluence dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

Prototype Pollution Axios Dependency in Confluence Data Center

CVE-2026-42264

9.1 Critical

This is a vulnerability in a non-Atlassian Confluence dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

SSRF (Server-Side Request Forgery) Axios Dependency in Confluence Data Center

CVE-2026-40175

9 Critical

This is a vulnerability in a non-Atlassian Confluence dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

Injection axios Dependency in Confluence Data Center

CVE-2026-44494

8.7 High

RCE (Remote Code Execution) form-data Dependency in Confluence Data Center

CVE-2026-12143

8.7 High

SSRF (Server-Side Request Forgery) axios Dependency in Confluence Data Center

CVE-2026-44492

8.6 High

Information Disclosure axios Dependency in Confluence Data Center

CVE-2026-44487

8.2 High

File Inclusion node-tar Dependency in Confluence Data Center

CVE-2026-31802

8.2 High

Injection axios Dependency in Confluence Data Center

CVE-2026-44490

8.2 High

Information Disclosure in Confluence Data Center

CVE-2026-21579

8.2 High

Injection axios Dependency in Confluence Data Center

CVE-2026-42041

8.2 High

DoS (Denial of Service) serialize-javascript Dependency in Confluence Data Center

CVE-2026-34043

7.5 High

DoS (Denial of Service) netty Dependency in Confluence Data Center

CVE-2026-42583

7.5 High

DoS (Denial of Service) axios Dependency in Confluence Data Center

CVE-2026-44496

7.5 High

DoS (Denial of Service) axios Dependency in Confluence Data Center

CVE-2026-44488

7.5 High

File Inclusion fast-uri Dependency in Confluence Data Center

CVE-2026-6321

7.5 High

Injection fast-uri Dependency in Confluence Data Center

CVE-2026-6322

7.5 High

Injection js-cookie Dependency in Confluence Data Center

CVE-2026-46625

7.5 High

DoS (Denial of Service) picomatch Dependency in Confluence Data Center

CVE-2026-33671

7.5 High

Information Disclosure axios Dependency in Confluence Data Center

CVE-2026-44486

7.5 High

DoS (Denial of Service) in Confluence Data Center

CVE-2026-48779

7.5 High

DoS (Denial of Service) io.netty:netty-codec-http Dependency in Confluence Data Center and Server

NOTE: We’ve issued updated fixed version guidance for this vulnerability. Please refer to the JAC ticket for more information.

CVE-2026-42587

7.5 High

Injection axios Dependency in Confluence Data Center

CVE-2026-42035

7.4 High

Injection axios Dependency in Confluence Data Center

CVE-2026-42033

7.4 High

DoS (Denial of Service) in Confluence Data Center

CVE-2026-21577

7.1 High

RCE (Remote Code Execution) axios Dependency in Confluence Data Center

CVE-2026-44495

7 High

Injection logback-core Dependency in Confluence Data Center

CVE-2025-11226

7 High

Crowd Data Center and Server

  • 7.2.0

  • 7.1.0 to 7.1.5

  • 6.3.1 to 6.3.6

  • 6.2.0 to 6.2.6

  • 6.1.3 to 6.1.7

  • 6.0.1 to 6.0.10

  • 5.3.3 to 5.3.8

  • 7.2.1 (LTS) recommended Data Center Only

RCE (Remote Code Execution) c3p0 Dependency in Crowd Data Center

CVE-2026-27830

8.9 High

Fisheye/Crucible

  • 4.9.0 to 4.9.11

  • 4.9.12 recommended

RCE (Remote Code Execution) com.google.protobuf:protobuf-java Dependency in Crucible Server

CVE-2024-7254

8.7 High

DoS (Denial of Service) com.google.protobuf:protobuf-java Dependency in Crucible Server

CVE-2022-3510

7.5 High

DoS (Denial of Service) com.google.protobuf:protobuf-java Dependency in Crucible Server

CVE-2022-3509

7.5 High

DoS (Denial of Service) com.google.protobuf:protobuf-java Dependency in Crucible Server

CVE-2021-22569

7.5 High

Jira Data Center and Server

  • 11.3.0 to 11.3.7 (LTS)

  • 11.2.0 to 11.2.1

  • 11.1.0 to 11.1.1

  • 11.0.0 to 11.0.1

  • 10.7.1 to 10.7.4

  • 10.6.0 to 10.6.1

  • 10.5.0 to 10.5.1

  • 10.4.0 to 10.4.1

  • 10.3.0 to 10.3.22 (LTS)

  • 10.2.0 to 10.2.1

  • 10.1.1 to 10.1.2

  • 10.0.0 to 10.0.1

  • 9.17.2 to 9.17.5

  • 9.12.12 to 9.12.36 (LTS)

  • 11.3.8 (LTS) recommended Data Center Only

  • 10.3.23 (LTS) Data Center Only

Prototype pollution vulnerability parseQuery dependency in Jira Software Data Center

CVE-2022-37601

9.8 Critical

This is a vulnerability in a non-Atlassian Jira Software dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

HTTP Request Smuggling io.netty:netty-codec-http Dependency in Jira Software Data Center

CVE-2026-42581

9.8 Critical

This is a vulnerability in a non-Atlassian Jira Software dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

Cryptographic Failure org.bouncycastle:bcprov Dependency in Jira Software Data Center

CVE-2025-14813

9.3 Critical

This is a vulnerability in a non-Atlassian Jira Software dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

BASM (Broken Authentication & Session Management) in Jira Software Data Center

CVE-2026-29145

9.1 Critical

This is a vulnerability in a non-Atlassian Jira Software dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

Prototype Pollution "Gadget" Axios Dependency in Jira Software Data Center

CVE-2026-42044

9.1 Critical

This is a vulnerability in a non-Atlassian Jira Software dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

Injection Immutable.js Dependency in Jira Software Data Center

CVE-2026-29063

8.7 High

File Inclusion node-tmp Dependency in Jira Software Data Center

CVE-2026-44705

7.7 High

Information Disclosure Apache Tomcat Dependency in Jira Software Data Center

CVE-2026-29146

7.5 High

DoS (Denial of Service) loader-utils Dependency in Jira Software Data Center

CVE-2022-37603

7.5 High

DoS (Denial of Service) loader-utils Dependency in Jira Software Data Center

CVE-2022-37599

7.5 High

File Inclusion fast-uri Dependency in Jira Software Data Center

CVE-2026-6321

7.5 High

Injection fast-uri Dependency in Jira Software Data Center

CVE-2026-6322

7.5 High

DoS (Denial of Service) pgjdbc Dependency in Jira Software Data Center

CVE-2026-42198

7.5 High

DoS (Denial of Service) ajv Dependency in Jira Software Data Center

CVE-2025-69873

7.5 High

Jira Service Management Data Center and Server

  • 11.3.0 to 11.3.7 (LTS)

  • 11.2.0 to 11.2.1

  • 11.1.0 to 11.1.1

  • 11.0.0 to 11.0.1

  • 10.7.1 to 10.7.4

  • 10.6.0 to 10.6.1

  • 10.5.0 to 10.5.1

  • 10.4.0 to 10.4.1

  • 10.3.0 to 10.3.22 (LTS)

  • 10.2.0 to 10.2.1

  • 10.1.1 to 10.1.2

  • 10.0.0 to 10.0.1

  • 5.17.2 to 5.17.5

  • 11.3.8 (LTS) recommended Data Center Only

  • 10.3.23 (LTS) Data Center Only

Prototype pollution vulnerability parseQuery dependency in Jira Software Data Center

CVE-2022-37601

9.8 Critical

This is a vulnerability in a non-Atlassian Jira Service Management dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

HTTP Request Smuggling io.netty:netty-codec-http Dependency in Jira Service Management Data Center

CVE-2026-42581

9.8 Critical

This is a vulnerability in a non-Atlassian Jira Service Management dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

Cryptographic Failure org.bouncycastle:bcprov Dependency in Jira Service Management Data Center

CVE-2025-14813

9.3 Critical

This is a vulnerability in a non-Atlassian Jira Service Management dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

BASM (Broken Authentication & Session Management) in Jira Service Management Data Center

CVE-2026-29145

9.1 Critical

This is a vulnerability in a non-Atlassian Jira Service Management dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

Prototype Pollution "Gadget" Axios Dependency in Jira Service Management Data Center

CVE-2026-42044

9.1 Critical

This is a vulnerability in a non-Atlassian Jira Service Management dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

Injection Immutable.js Dependency in Jira Service Management Data Center

CVE-2026-29063

8.7 High

BASM (Broken Authentication & Session Management) SubjectDnX509PrincipalExtractor Dependency in Jira Service Management Data Center

CVE-2026-47838

8.1 High

File Inclusion node-tmp Dependency in Jira Service Management Data Center

CVE-2026-44705

7.7 High

Information Disclosure Apache Tomcat Dependency in Jira Service Management Data Center

CVE-2026-29146

7.5 High

File Inclusion fast-uri Dependency in Jira Service Management Data Center

CVE-2026-6321

7.5 High

DoS (Denial of Service) ajv Dependency in Jira Service Management Data Center

CVE-2025-69873

7.5 High

DoS (Denial of Service) loader-utils Dependency in Jira Service Management Data Center

CVE-2022-37599

7.5 High

DoS (Denial of Service) loader-utils Dependency in Jira Service Management Data Center

CVE-2022-37603

7.5 High

DoS (Denial of Service) pgjdbc Dependency in Jira Service Management Data Center

CVE-2026-42198

7.5 High

Injection fast-uri Dependency in Jira Service Management Data Center

CVE-2026-6322

7.5 High

Sourcetree for Mac

  • All versions from 3.4.11 to 3.4.12

  • All versions from 3.4.13

RCE (Remote Code Execution) in Sourcetree for Mac and Sourcetree for Windows

CVE-2026-21575

7.1 High

Sourcetree for Windows

  • All versions from 3.4.11 to 3.4.12

  • All versions from 3.4.13

RCE (Remote Code Execution) in Sourcetree for Mac and Sourcetree for Windows

CVE-2026-21575

7.1 High


Frequently Asked Questions:

  • Why is my Feature Version not listed in a Fixed Version? You may be using an unsupported version and need to patch to the latest version or Long-Term Support (LTS) version.

  • What are the most up-to-date Data Center product versions? You can always check the software download portal or visit the product-specific download pages.

  • I am using an LTS, why is it not listed in the Fixed Versions? Your LTS version may not have been updated yet or a backported fix may not have been feasible. Please see our Security Bug Fix Policy for more information. We recommend upgrading your products to the latest versions. For the latest fixed versions, visit the release notes linked in the vulnerability table.

  • Questions about the bulletin, have feedback? Let us know! Read more about our bulletins and feel free to contribute feedback on our latest Community Post


To search for CVEs or check your products versions for disclosed vulnerabilities, check the Vulnerability Disclosure Portal.

Last modified on Jul 22, 2026

Was this helpful?

Yes
No
Provide feedback about this article
Powered by Confluence and Scroll Viewport.