17 lutego 2026 r. firma Atlassian opublikowała ostrzeżenie dotyczące bezpieczeństwa w celu usunięcia luk w zabezpieczeniach następujących produktów:

• Bamboo Data Center i Server – wiele wersji

• Confluence Data Center i Server – wiele wersji

• Crowd Data Center i Server – wiele wersji

ProduktPodatna wersjaPatchLink/OpisCVE IDCVSS
Bamboo Data Center and Server12.1.0 (LTS) 12.0.1 do 12.0.2 11.0.7 do 11.0.8 10.2.9 do 10.2.13 (LTS)12.1.2 (LTS) rekomendowany tylko Data Center 10.2.14 do 10.2.15 (LTS) tylko Data CenterDOM-based XSS com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer Dependency in Bamboo Data Center and ServerCVE-2025-660218.6 Wysoka
Confluence Data Center and Server10.2.0 do 10.2.2 (LTS) 10.1.0 do 10.1.2 10.0.2 do 10.0.3 9.5.1 do 9.5.4 9.4.0 do 9.4.1 9.3.1 do 9.3.2 9.2.0 do 9.2.13 (LTS) 9.1.0 do 9.1.1 9.0.1 do 9.0.3 8.9.0 do 8.9.8 8.8.1 8.5.7 do 8.5.31 (LTS) 7.19.20 do 7.19.30 (LTS)10.2.6 (LTS) rekomendowany tylko Data Center 10.2.3 (LTS) tylko Data Center   9.2.15 rekomendowany (LTS) tylko Data Center 9.2.14 (LTS) tylko Data CenterFile Inclusion tar-fs Dependency in Confluence Data Center and ServerCVE-2025-593438.7 Wysoka
DoS (Denial of Service) in Confluence Data Center and ServerCVE-2022-258837.5 Wysoka
DoS (Denial of Service) in Confluence Data Center and ServerCVE-2020-284697.5 Wysoka
Improper Authorization org.springframework:spring-core Dependency in Confluence Data Center and ServerCVE-2025-412497.5 Wysoka
DoS (Denial of Service) in Confluence Data Center and ServerCVE-2025-489767.5 Wysoka
DoS (Denial of Service) in Confluence Data Center and ServerCVE-2022-259277.5 Wysoka
Crowd Data Center and Server7.1.0 do 7.1.3 7.0.0 do 7.0.2 6.3.0 do 6.3.4 6.2.0 do 6.2.6 6.1.0 do 6.1.7 6.0.0 do 6.0.10 5.3.1 do 5.3.8 5.1.13 5.0.117.1.4 rekomendowany tylko Data CenterXXE (XML External Entity Injection) org.apache.tika:tika-parsers Dependency in Crowd Data Center and ServerCVE-2025-665169.8 Krytyczna *
Injection in Crowd Data Center and ServerCVE-2025-92889.1 Krytyczna *
Injection in Crowd Data Center and ServerCVE-2025-92879.1 Krytyczna *
RCE (Remote Code Execution) commons-beanutils Dependency in Crowd Data Center and ServerCVE-2025-487348.8 Wysoka
DoS (Denial of Service) org.apache.struts:struts2-core Dependency in Crowd Data Center and ServerCVE-2025-666758.2 Wysoka
DoS (Denial of Service) in Crowd Data Center and ServerCVE-2020-284697.5 Wysoka
DoS (Denial of Service) in Crowd Data Center and ServerCVE-2022-259277.5 Wysoka
Insecure Deserialization kind-of Dependency in Crowd Data Center and ServerCVE-2019-201497.5 Wysoka
DoS (Denial of Service) Third-Party Dependency in Crowd Data Center and ServerCVE-2024-576997.5 Wysoka