16 czerwca 2026 r. firma Atlassian opublikowała ostrzeżenie dotyczące bezpieczeństwa w celu usunięcia luk w zabezpieczeniach, w tym kilku krytycznych, w następujących produktach:

  • Bamboo Data Center i Server – wiele wersji
  • Bitbucket Data Center i Server – wiele wersji
  • Confluence Data Center i Server – wiele wersji
  • Crowd Data Center i Server – wiele wersji
  • Fisheye/Crucible – wersje od 4.9.0 do 4.9.10
  • Jira Data Center i Server – wiele wersji
  • Jira Service Management Data Center i Server – wiele wersji
ProduktPodatna wersjaPatchLink/OpisNumer CVEKrytyczność
Bamboo Data Center and Server12.1.0 to 12.1.7 (LTS) 12.0.0 to 12.0.2 11.0.0 to 11.0.8 10.2.0 to 10.2.19 (LTS) 10.1.0 to 10.1.1 10.0.0 to 10.0.312.1.8 (LTS) rekomendowane tylko Data Center 10.2.20 (LTS) Tylko Data CenterRCE (Remote Code Execution) org.apache.activemq:activemq-broker Dependency in Bamboo Data CenterCVE-2026-410448.8/10 Wysoka
SSRF (Server-Side Request Forgery) axios Dependency in Bamboo Data CenterCVE-2026-444928.6/10 Wysoka
Information Disclosure axios Dependency in Bamboo Data CenterCVE-2026-444878.2/10 Wysoka
DoS (Denial of Service) axios Dependency in Bamboo Data CenterCVE-2026-444887.5/10 Wysoka
HTTP Request Smuggling io.netty:netty-codec-http Dependency in Bamboo Data CenterCVE-2026-425857.5/10 Wysoka
DoS (Denial of Service) io.netty:netty-codec Dependency in Bamboo Data CenterCVE-2026-425837.5/10 Wysoka
Information Disclosure axios Dependency in Bamboo Data CenterCVE-2026-444867.5/10 Wysoka
SSRF (Server-Side Request Forgery) axios Dependency in Bamboo Data CenterCVE-2026-420387.5/10 Wysoka
DoS (Denial of Service) org.apache.tomcat:tomcat-catalina Dependency in Bamboo Data CenterCVE-2026-412847.5/10 Wysoka
DoS (Denial of Service) axios Dependency in Bamboo Data CenterCVE-2026-444967.5/10 Wysoka
DoS (Denial of Service) io.netty:netty-codec Dependency in Bamboo Data CenterCVE-2026-425877.5/10 Wysoka
Business Logic Vulnerability org.apache.tomcat:tomcat-catalina Dependency in Bamboo Data CenterCVE-2026-435137.5/10 Wysoka
DoS (Denial of Service) org.postgresql:postgresql Dependency in Bamboo Data CenterCVE-2026-410447.5/10 Wysoka
Injection axios Dependency in Bamboo Data CenterCVE-2026-420337.4/10 Wysoka
Injection axios Dependency in Bamboo Data CenterCVE-2026-420357.4/10 Wysoka
Bitbucket Data Center and Server10.3.0 10.2.0 to 10.2.3 (LTS) 10.1.1 to 10.1.5 10.0.0 to 10.0.2 9.6.0 to 9.6.5 9.5.0 to 9.5.2 9.4.0 to 9.4.20 (LTS) 9.3.0 to 9.3.2 9.2.0 to 9.2.1 9.1.0 to 9.1.1 9.0.110.3.1 Tylko Data Center 10.2.4 (LTS) rekomendowane tylko Data Center 9.4.21 (LTS) Tylko Data CenterSSRF (Server-Side Request Forgery) axios Dependency in Bitbucket Data CenterCVE-2026-420387.5/10 Wysoka
DoS (Denial of Service) @isaacs/brace-expansion Dependency in Bitbucket Data CenterCVE-2026-451497.5/10 Wysoka
DoS (Denial of Service) org.apache.tomcat.embed:tomcat-embed-core Dependency in Bitbucket Data CenterCVE-2026-412847.5/10 Wysoka
MITM (Man-in-the-Middle) org.apache.tomcat.embed:tomcat-embed-core Dependency in Bitbucket Data CenterCVE-2026-247347.5/10 Wysoka
Injection axios Dependency in Bitbucket Data CenterCVE-2026-420337.4/10 Wysoka
Injection axios Dependency in Bitbucket Data CenterCVE-2026-420357.4/10 Wysoka
Confluence Data Center and Server10.2.0 to 10.2.11 (LTS) 10.1.0 to 10.1.2 10.0.2 to 10.0.3 9.5.1 to 9.5.4 9.4.0 to 9.4.1 9.3.1 to 9.3.2 9.2.0 to 9.2.20 (LTS) 9.1.0 to 9.1.1 9.0.1 to 9.0.3 8.9.4 to 8.9.8 8.5.12 to 8.5.31 (LTS) 7.19.25 to 7.19.30 (LTS)10.2.13 (LTS) rekomendowane tylko Data Center 9.2.21 (LTS) Tylko Data CenterInjection org.apache.tomcat:tomcat-coyote Dependency in Confluence Data CenterCVE-2026-412939.8/10 Krytyczna
BASM (Broken Authentication & Session Management) org.apache.tomcat:tomcat-catalina Dependency in Confluence Data Center and ServerCVE-2026-435129.8/10 Krytyczna
Injection io.netty:netty-codec-dns Dependency in Confluence Data CenterCVE-2026-425799.1/10 Krytyczna
HTTP Request Smuggling io.netty:netty-codec-http Dependency in Confluence Data CenterCVE-2026-425849.1/10 Krytyczna
Improper Authorization org.apache.tomcat:tomcat-catalina Dependency in Confluence Data CenterCVE-2026-435159.1/10 Krytyczna
DoS (Denial of Service) minimatch Dependency in Confluence Data CenterCVE-2026-269968.7/10 Wysoka
DoS (Denial of Service) org.apache.tomcat:tomcat-catalina Dependency in Confluence Data CenterCVE-2026-412847.5/10 Wysoka
Business Logic Vulnerability Apache Tomcat Dependency in Confluence Data CenterCVE-2026-435137.5/10 Wysoka
HTTP Request Smuggling ws Dependency in Confluence Data CenterCVE-2026-457367.5/10 Wysoka
HTTP Request Smuggling io.netty:netty-codec-http Dependency in Confluence Data CenterCVE-2026-425857.5/10 Wysoka
DoS (Denial of Service) minimatch Dependency in Confluence Data CenterCVE-2026-279047.5/10 Wysoka
DoS (Denial of Service) minimatch Dependency in Confluence Data CenterCVE-2026-279037.5/10 Wysoka
DoS (Denial of Service) @isaacs/brace-expansion Dependency in Confluence Data CenterCVE-2026-451497.5/10 Wysoka
DoS (Denial of Service) io.netty:netty-codec-http Dependency in Confluence Data Center and ServerCVE-2026-425877.5/10 Wysoka
Information Disclosure org.apache.tomcat:tomcat-websocket Dependency in Confluence Data CenterCVE-2026-424987.3/10 Wysoka
Crowd Data Center and Server7.2.0 7.1.0 to 7.1.5 7.0.0 to 7.0.2 6.3.0 to 6.3.6 6.2.0 to 6.2.6 6.1.0 to 6.1.7 6.0.0 to 6.0.10 5.3.2 to 5.3.87.2.1 rekomendowane tylko Data CenterHTTP Request Smuggling io.netty:netty-codec-http Dependency in Crowd Data CenterCVE-2026-425819.8/10 Krytyczna
Business Logic Vulnerability org.springframework.security:spring-security-web Dependency in Crowd Data CenterCVE-2026-227329.1/10 Krytyczna
HTTP Request Smuggling io.netty:netty-codec-http Dependency in Crowd Data CenterCVE-2026-425849.1/10 Krytyczna
DoS (Denial of Service) org.postgresql:postgresql Dependency in Crowd Data CenterCVE-2026-421987.5/10 Wysoka
DoS (Denial of Service) io.netty:netty-codec Dependency in Crowd Data CenterCVE-2026-425837.5/10 Wysoka
HTTP Request Smuggling io.netty:netty-codec-http Dependency in Crowd Data CenterCVE-2026-425857.5/10 Wysoka
DoS (Denial of Service) io.netty:netty-codec-http2 Dependency in Crowd Data CenterCVE-2026-425877.5/10 Wysoka
Fisheye/Crucible4.9.0 to 4.9.104.9.11 rekomendowaneImproper Authorization org.springframework.security:spring-security-core Dependency in Crucible Data Center and ServerCVE-2024-222578.2/10 Wysoka
BASM (Broken Authentication & Session Management) org.springframework.security:spring-security-core Dependency in Crucible Data Center and ServerCVE-2025-222287.4/10 Wysoka
BASM (Broken Authentication & Session Management) org.springframework.security:spring-security-core Dependency in Crucible Data Center and ServerCVE-2019-112727.3/10 Wysoka
Jira Data Center and Server11.3.0 to 11.3.6 (LTS) 11.2.0 to 11.2.1 11.1.0 to 11.1.1 11.0.0 to 11.0.1 10.7.1 to 10.7.4 10.6.0 to 10.6.1 10.5.0 to 10.5.1 10.4.0 to 10.4.1 10.3.0 to 10.3.21 (LTS) 10.2.0 to 10.2.1 10.1.1 to 10.1.2 10.0.0 to 10.0.1 9.17.0 to 9.17.5 9.12.11 to 9.12.35 (LTS)11.3.7 (LTS) rekomendowane tylko Data Center 10.3.22 (LTS) Tylko Data CenterSSRF (Server-Side Request Forgery) axios Dependency in Jira Software Data CenterCVE-2026-4204310/10 Krytyczna
Prototype Pollution axios Dependency in Jira Software Data Center and ServerCVE-2026-4017510/10 Krytyczna
Injection org.apache.tomcat:tomcat-catalina Dependency in Jira Software Data CenterCVE-2026-412939.8/10 Krytyczna
BASM (Broken Authentication & Session Management) org.apache.tomcat:tomcat-catalina Dependency in Jira Software Data Center and ServerCVE-2026-435129.8/10 Krytyczna
Injection org.apache.tomcat:tomcat-coyote Dependency in Jira Software Data CenterCVE-2026-412939.8/10 Krytyczna
Improper Authorization org.apache.tomcat:tomcat-coyote Dependency in Jira Software Data CenterCVE-2026-435159.1/10 Krytyczna
Improper Authorization org.apache.tomcat:tomcat-catalina Dependency in Jira Software Data CenterCVE-2026-435159.1/10 Krytyczna
HTTP Request Smuggling io.netty:netty-codec-http Dependency in Jira Software Data CenterCVE-2026-425849.1/10 Krytyczna
Injection axios Dependency in Jira Software Data CenterCVE-2026-422649.1/10 Krytyczna
DoS (Denial of Service) io.netty:netty-codec-http2 Dependency in Jira Software Data CenterCVE-2026-338718.7/10 Wysoka
RCE (Remote Code Execution) react-router Dependency in Jira Software Data CenterCVE-2026-422118.1/10 Wysoka
XSS (Cross Site Scripting) turbo-stream Dependency in Jira Software Data CenterCVE-2026-340777.5/10 Wysoka
Information Disclosure org.apache.tomcat:tomcat-catalina Dependency in Jira Software Data CenterCVE-2026-344877.5/10 Wysoka
HTTP Request Smuggling io.netty:netty-codec-http Dependency in Jira Data CenterCVE-2026-425857.5/10 Wysoka
DoS (Denial of Service) org.apache.tomcat:tomcat-catalina Dependency in Jira Software Data CenterCVE-2026-412847.5/10 Wysoka
DoS (Denial of Service) nth-check Dependency in Jira Software Data CenterCVE-2021-38037.5/10 Wysoka
Business Logic Vulnerability Apache Tomcat Dependency in Jira Software Data CenterCVE-2026-435137.5/10 Wysoka
DoS (Denial of Service) minimatch Dependency in Jira Software Data CenterCVE-2026-279037.5/10 Wysoka
DoS (Denial of Service) react-router Dependency in Jira Software Data CenterCVE-2026-423427.5/10 Wysoka
HTTP Request Smuggling io.netty:netty-codec-http Dependency in Jira Software Data CenterCVE-2026-338707.5/10 Wysoka
SSRF (Server-Side Request Forgery) axios Dependency in Jira Software Data CenterCVE-2026-420387.5/10 Wysoka
DoS (Denial of Service) minimatch Dependency in Jira Software Data CenterCVE-2026-279047.5/10 Wysoka
Cryptographic Failure org.apache.tomcat:tomcat-catalina Dependency in Jira Software Data CenterCVE-2026-344867.5/10 Wysoka
Injection axios Dependency in Jira Software Data CenterCVE-2026-420357.4/10 Wysoka
Injection axios Dependency in Jira Software Data CenterCVE-2026-420337.4/10 Wysoka
RCE (Remote Code Execution) axios Dependency in Jira Software Data CenterCVE-2026-444957/10 Wysoka
Jira Service Management Data Center and Server11.3.0 to 11.3.6 (LTS) 11.2.0 to 11.2.1 11.1.0 to 11.1.1 11.0.0 to 11.0.1 10.7.1 to 10.7.4 10.6.0 to 10.6.1 10.5.0 to 10.5.1 10.4.0 to 10.4.1 10.3.0 to 10.3.21 (LTS) 10.2.0 to 10.2.1 10.1.1 to 10.1.2 10.0.0 to 10.0.1 5.17.0 to 5.17.511.3.7 (LTS) rekomendowane tylko Data Center 10.3.22 (LTS) Tylko Data CenterPrototype Pollution axios Dependency in Jira Service Management Data Center and ServerCVE-2026-4017510/10 Krytyczna
SSRF (Server-Side Request Forgery) axios Dependency in Jira Service Management Data CenterCVE-2026-4204310/10 Krytyczna
Injection org.apache.tomcat:tomcat-coyote Dependency in Jira Service Management Data CenterCVE-2026-412939.8/10 Krytyczna
Authentication Bypass org.apache.tomcat:tomcat-catalina Dependency in Jira Service Management Data CenterCVE-2026-435129.8/10 Krytyczna
HTTP Request Smuggling io.netty:netty-codec-http Dependency in Jira Service Management Data CenterCVE-2026-425849.1/10 Krytyczna
Improper Authorization org.apache.tomcat:tomcat-catalina Dependency in Jira Service Management Data CenterCVE-2026-435159.1/10 Krytyczna
Injection axios Dependency in Jira Service Management Data CenterCVE-2026-422649.1/10 Krytyczna
DoS (Denial of Service) io.netty:netty-codec-http2 Dependency in Jira Service Management Data CenterCVE-2026-338718.7/10 Wysoka
RCE (Remote Code Execution) react-router Dependency in Jira Service Management Data CenterCVE-2026-422118.1/10 Wysoka
DoS (Denial of Service) io.netty:netty-codec Dependency in Jira Service Management Data CenterCVE-2026-425877.5/10 Wysoka
XSS (Cross Site Scripting) turbo-stream Dependency in Jira Service Management Data CenterCVE-2026-340777.5/10 Wysoka
DoS (Denial of Service) minimatch Dependency in Jira Service Management Data CenterCVE-2026-279037.5/10 Wysoka
HTTP Request Smuggling io.netty:netty-codec-http Dependency in Jira Service Management Data CenterCVE-2026-425857.5/10 Wysoka
Security Misconfiguration org.apache.tomcat:tomcat-catalina Dependency in Jira Service Management Data CenterCVE-2026-344867.5/10 Wysoka
DoS (Denial of Service) org.apache.tomcat:tomcat-catalina Dependency in Jira Service Management Data CenterCVE-2026-412847.5/10 Wysoka
DoS (Denial of Service) minimatch Dependency in Jira Service Management Data CenterCVE-2026-279047.5/10 Wysoka
DoS (Denial of Service) io.netty:netty-codec Dependency in Jira Service Management Data CenterCVE-2026-425837.5/10 Wysoka
SSRF (Server-Side Request Forgery) axios Dependency in Jira Service Management Data CenterCVE-2026-420387.5/10 Wysoka
Business Logic Vulnerability Apache Tomcat Dependency in Jira Service Management Data CenterCVE-2026-435137.5/10 Wysoka
DoS (Denial of Service) nth-check Dependency in Jira Service Management Data CenterCVE-2021-38037.5/10 Wysoka
DoS (Denial of Service) react-router Dependency in Jira Service Management Data CenterCVE-2026-423427.5/10 Wysoka
Cryptographic Failure org.apache.tomcat:tomcat-catalina Dependency in Jira Service Management Data CenterCVE-2026-291297.5/10 Wysoka
HTTP Request Smuggling io.netty:netty-codec-http Dependency in Jira Service Management Data CenterCVE-2026-338707.5/10 Wysoka
Information Disclosure org.apache.tomcat:tomcat-catalina Dependency in Jira Service Management Data CenterCVE-2026-344877.5/10 Wysoka
Injection axios Dependency in Jira Service Management Data CenterCVE-2026-420357.4/10 Wysoka
Injection axios Dependency in Jira Service Management Data CenterCVE-2026-420337.4/10 Wysoka
Information Disclosure org.apache.tomcat:tomcat-websocket Dependency in Jira Service Management Data Center and ServerCVE-2026-424987.3/10 Wysoka
RCE (Remote Code Execution) axios Dependency in Jira Service Management Data CenterCVE-2026-444957/10 Wysoka