| Produkt | Podatna wersja | Patch | Link/Opis | Numer CVE | Krytyczność |
| Bamboo Data Center and Server | 12.1.0 to 12.1.7 (LTS) 12.0.0 to 12.0.2 11.0.0 to 11.0.8 10.2.0 to 10.2.19 (LTS) 10.1.0 to 10.1.1 10.0.0 to 10.0.3 | 12.1.8 (LTS) rekomendowane tylko Data Center 10.2.20 (LTS) Tylko Data Center | RCE (Remote Code Execution) org.apache.activemq:activemq-broker Dependency in Bamboo Data Center | CVE-2026-41044 | 8.8/10 Wysoka |
| SSRF (Server-Side Request Forgery) axios Dependency in Bamboo Data Center | CVE-2026-44492 | 8.6/10 Wysoka |
| Information Disclosure axios Dependency in Bamboo Data Center | CVE-2026-44487 | 8.2/10 Wysoka |
| DoS (Denial of Service) axios Dependency in Bamboo Data Center | CVE-2026-44488 | 7.5/10 Wysoka |
| HTTP Request Smuggling io.netty:netty-codec-http Dependency in Bamboo Data Center | CVE-2026-42585 | 7.5/10 Wysoka |
| DoS (Denial of Service) io.netty:netty-codec Dependency in Bamboo Data Center | CVE-2026-42583 | 7.5/10 Wysoka |
| Information Disclosure axios Dependency in Bamboo Data Center | CVE-2026-44486 | 7.5/10 Wysoka |
| SSRF (Server-Side Request Forgery) axios Dependency in Bamboo Data Center | CVE-2026-42038 | 7.5/10 Wysoka |
| DoS (Denial of Service) org.apache.tomcat:tomcat-catalina Dependency in Bamboo Data Center | CVE-2026-41284 | 7.5/10 Wysoka |
| DoS (Denial of Service) axios Dependency in Bamboo Data Center | CVE-2026-44496 | 7.5/10 Wysoka |
| DoS (Denial of Service) io.netty:netty-codec Dependency in Bamboo Data Center | CVE-2026-42587 | 7.5/10 Wysoka |
| Business Logic Vulnerability org.apache.tomcat:tomcat-catalina Dependency in Bamboo Data Center | CVE-2026-43513 | 7.5/10 Wysoka |
| DoS (Denial of Service) org.postgresql:postgresql Dependency in Bamboo Data Center | CVE-2026-41044 | 7.5/10 Wysoka |
| Injection axios Dependency in Bamboo Data Center | CVE-2026-42033 | 7.4/10 Wysoka |
| Injection axios Dependency in Bamboo Data Center | CVE-2026-42035 | 7.4/10 Wysoka |
| Bitbucket Data Center and Server | 10.3.0 10.2.0 to 10.2.3 (LTS) 10.1.1 to 10.1.5 10.0.0 to 10.0.2 9.6.0 to 9.6.5 9.5.0 to 9.5.2 9.4.0 to 9.4.20 (LTS) 9.3.0 to 9.3.2 9.2.0 to 9.2.1 9.1.0 to 9.1.1 9.0.1 | 10.3.1 Tylko Data Center 10.2.4 (LTS) rekomendowane tylko Data Center 9.4.21 (LTS) Tylko Data Center | SSRF (Server-Side Request Forgery) axios Dependency in Bitbucket Data Center | CVE-2026-42038 | 7.5/10 Wysoka |
| DoS (Denial of Service) @isaacs/brace-expansion Dependency in Bitbucket Data Center | CVE-2026-45149 | 7.5/10 Wysoka |
| DoS (Denial of Service) org.apache.tomcat.embed:tomcat-embed-core Dependency in Bitbucket Data Center | CVE-2026-41284 | 7.5/10 Wysoka |
| MITM (Man-in-the-Middle) org.apache.tomcat.embed:tomcat-embed-core Dependency in Bitbucket Data Center | CVE-2026-24734 | 7.5/10 Wysoka |
| Injection axios Dependency in Bitbucket Data Center | CVE-2026-42033 | 7.4/10 Wysoka |
| Injection axios Dependency in Bitbucket Data Center | CVE-2026-42035 | 7.4/10 Wysoka |
| Confluence Data Center and Server | 10.2.0 to 10.2.11 (LTS) 10.1.0 to 10.1.2 10.0.2 to 10.0.3 9.5.1 to 9.5.4 9.4.0 to 9.4.1 9.3.1 to 9.3.2 9.2.0 to 9.2.20 (LTS) 9.1.0 to 9.1.1 9.0.1 to 9.0.3 8.9.4 to 8.9.8 8.5.12 to 8.5.31 (LTS) 7.19.25 to 7.19.30 (LTS) | 10.2.13 (LTS) rekomendowane tylko Data Center 9.2.21 (LTS) Tylko Data Center | Injection org.apache.tomcat:tomcat-coyote Dependency in Confluence Data Center | CVE-2026-41293 | 9.8/10 Krytyczna |
| BASM (Broken Authentication & Session Management) org.apache.tomcat:tomcat-catalina Dependency in Confluence Data Center and Server | CVE-2026-43512 | 9.8/10 Krytyczna |
| Injection io.netty:netty-codec-dns Dependency in Confluence Data Center | CVE-2026-42579 | 9.1/10 Krytyczna |
| HTTP Request Smuggling io.netty:netty-codec-http Dependency in Confluence Data Center | CVE-2026-42584 | 9.1/10 Krytyczna |
| Improper Authorization org.apache.tomcat:tomcat-catalina Dependency in Confluence Data Center | CVE-2026-43515 | 9.1/10 Krytyczna |
| DoS (Denial of Service) minimatch Dependency in Confluence Data Center | CVE-2026-26996 | 8.7/10 Wysoka |
| DoS (Denial of Service) org.apache.tomcat:tomcat-catalina Dependency in Confluence Data Center | CVE-2026-41284 | 7.5/10 Wysoka |
| Business Logic Vulnerability Apache Tomcat Dependency in Confluence Data Center | CVE-2026-43513 | 7.5/10 Wysoka |
| HTTP Request Smuggling ws Dependency in Confluence Data Center | CVE-2026-45736 | 7.5/10 Wysoka |
| HTTP Request Smuggling io.netty:netty-codec-http Dependency in Confluence Data Center | CVE-2026-42585 | 7.5/10 Wysoka |
| DoS (Denial of Service) minimatch Dependency in Confluence Data Center | CVE-2026-27904 | 7.5/10 Wysoka |
| DoS (Denial of Service) minimatch Dependency in Confluence Data Center | CVE-2026-27903 | 7.5/10 Wysoka |
| DoS (Denial of Service) @isaacs/brace-expansion Dependency in Confluence Data Center | CVE-2026-45149 | 7.5/10 Wysoka |
| DoS (Denial of Service) io.netty:netty-codec-http Dependency in Confluence Data Center and Server | CVE-2026-42587 | 7.5/10 Wysoka |
| Information Disclosure org.apache.tomcat:tomcat-websocket Dependency in Confluence Data Center | CVE-2026-42498 | 7.3/10 Wysoka |
| Crowd Data Center and Server | 7.2.0 7.1.0 to 7.1.5 7.0.0 to 7.0.2 6.3.0 to 6.3.6 6.2.0 to 6.2.6 6.1.0 to 6.1.7 6.0.0 to 6.0.10 5.3.2 to 5.3.8 | 7.2.1 rekomendowane tylko Data Center | HTTP Request Smuggling io.netty:netty-codec-http Dependency in Crowd Data Center | CVE-2026-42581 | 9.8/10 Krytyczna |
| Business Logic Vulnerability org.springframework.security:spring-security-web Dependency in Crowd Data Center | CVE-2026-22732 | 9.1/10 Krytyczna |
| HTTP Request Smuggling io.netty:netty-codec-http Dependency in Crowd Data Center | CVE-2026-42584 | 9.1/10 Krytyczna |
| DoS (Denial of Service) org.postgresql:postgresql Dependency in Crowd Data Center | CVE-2026-42198 | 7.5/10 Wysoka |
| DoS (Denial of Service) io.netty:netty-codec Dependency in Crowd Data Center | CVE-2026-42583 | 7.5/10 Wysoka |
| HTTP Request Smuggling io.netty:netty-codec-http Dependency in Crowd Data Center | CVE-2026-42585 | 7.5/10 Wysoka |
| DoS (Denial of Service) io.netty:netty-codec-http2 Dependency in Crowd Data Center | CVE-2026-42587 | 7.5/10 Wysoka |
| Fisheye/Crucible | 4.9.0 to 4.9.10 | 4.9.11 rekomendowane | Improper Authorization org.springframework.security:spring-security-core Dependency in Crucible Data Center and Server | CVE-2024-22257 | 8.2/10 Wysoka |
| BASM (Broken Authentication & Session Management) org.springframework.security:spring-security-core Dependency in Crucible Data Center and Server | CVE-2025-22228 | 7.4/10 Wysoka |
| BASM (Broken Authentication & Session Management) org.springframework.security:spring-security-core Dependency in Crucible Data Center and Server | CVE-2019-11272 | 7.3/10 Wysoka |
| Jira Data Center and Server | 11.3.0 to 11.3.6 (LTS) 11.2.0 to 11.2.1 11.1.0 to 11.1.1 11.0.0 to 11.0.1 10.7.1 to 10.7.4 10.6.0 to 10.6.1 10.5.0 to 10.5.1 10.4.0 to 10.4.1 10.3.0 to 10.3.21 (LTS) 10.2.0 to 10.2.1 10.1.1 to 10.1.2 10.0.0 to 10.0.1 9.17.0 to 9.17.5 9.12.11 to 9.12.35 (LTS) | 11.3.7 (LTS) rekomendowane tylko Data Center 10.3.22 (LTS) Tylko Data Center | SSRF (Server-Side Request Forgery) axios Dependency in Jira Software Data Center | CVE-2026-42043 | 10/10 Krytyczna |
| Prototype Pollution axios Dependency in Jira Software Data Center and Server | CVE-2026-40175 | 10/10 Krytyczna |
| Injection org.apache.tomcat:tomcat-catalina Dependency in Jira Software Data Center | CVE-2026-41293 | 9.8/10 Krytyczna |
| BASM (Broken Authentication & Session Management) org.apache.tomcat:tomcat-catalina Dependency in Jira Software Data Center and Server | CVE-2026-43512 | 9.8/10 Krytyczna |
| Injection org.apache.tomcat:tomcat-coyote Dependency in Jira Software Data Center | CVE-2026-41293 | 9.8/10 Krytyczna |
| Improper Authorization org.apache.tomcat:tomcat-coyote Dependency in Jira Software Data Center | CVE-2026-43515 | 9.1/10 Krytyczna |
| Improper Authorization org.apache.tomcat:tomcat-catalina Dependency in Jira Software Data Center | CVE-2026-43515 | 9.1/10 Krytyczna |
| HTTP Request Smuggling io.netty:netty-codec-http Dependency in Jira Software Data Center | CVE-2026-42584 | 9.1/10 Krytyczna |
| Injection axios Dependency in Jira Software Data Center | CVE-2026-42264 | 9.1/10 Krytyczna |
| DoS (Denial of Service) io.netty:netty-codec-http2 Dependency in Jira Software Data Center | CVE-2026-33871 | 8.7/10 Wysoka |
| RCE (Remote Code Execution) react-router Dependency in Jira Software Data Center | CVE-2026-42211 | 8.1/10 Wysoka |
| XSS (Cross Site Scripting) turbo-stream Dependency in Jira Software Data Center | CVE-2026-34077 | 7.5/10 Wysoka |
| Information Disclosure org.apache.tomcat:tomcat-catalina Dependency in Jira Software Data Center | CVE-2026-34487 | 7.5/10 Wysoka |
| HTTP Request Smuggling io.netty:netty-codec-http Dependency in Jira Data Center | CVE-2026-42585 | 7.5/10 Wysoka |
| DoS (Denial of Service) org.apache.tomcat:tomcat-catalina Dependency in Jira Software Data Center | CVE-2026-41284 | 7.5/10 Wysoka |
| DoS (Denial of Service) nth-check Dependency in Jira Software Data Center | CVE-2021-3803 | 7.5/10 Wysoka |
| Business Logic Vulnerability Apache Tomcat Dependency in Jira Software Data Center | CVE-2026-43513 | 7.5/10 Wysoka |
| DoS (Denial of Service) minimatch Dependency in Jira Software Data Center | CVE-2026-27903 | 7.5/10 Wysoka |
| DoS (Denial of Service) react-router Dependency in Jira Software Data Center | CVE-2026-42342 | 7.5/10 Wysoka |
| HTTP Request Smuggling io.netty:netty-codec-http Dependency in Jira Software Data Center | CVE-2026-33870 | 7.5/10 Wysoka |
| SSRF (Server-Side Request Forgery) axios Dependency in Jira Software Data Center | CVE-2026-42038 | 7.5/10 Wysoka |
| DoS (Denial of Service) minimatch Dependency in Jira Software Data Center | CVE-2026-27904 | 7.5/10 Wysoka |
| Cryptographic Failure org.apache.tomcat:tomcat-catalina Dependency in Jira Software Data Center | CVE-2026-34486 | 7.5/10 Wysoka |
| Injection axios Dependency in Jira Software Data Center | CVE-2026-42035 | 7.4/10 Wysoka |
| Injection axios Dependency in Jira Software Data Center | CVE-2026-42033 | 7.4/10 Wysoka |
| RCE (Remote Code Execution) axios Dependency in Jira Software Data Center | CVE-2026-44495 | 7/10 Wysoka |
| Jira Service Management Data Center and Server | 11.3.0 to 11.3.6 (LTS) 11.2.0 to 11.2.1 11.1.0 to 11.1.1 11.0.0 to 11.0.1 10.7.1 to 10.7.4 10.6.0 to 10.6.1 10.5.0 to 10.5.1 10.4.0 to 10.4.1 10.3.0 to 10.3.21 (LTS) 10.2.0 to 10.2.1 10.1.1 to 10.1.2 10.0.0 to 10.0.1 5.17.0 to 5.17.5 | 11.3.7 (LTS) rekomendowane tylko Data Center 10.3.22 (LTS) Tylko Data Center | Prototype Pollution axios Dependency in Jira Service Management Data Center and Server | CVE-2026-40175 | 10/10 Krytyczna |
| SSRF (Server-Side Request Forgery) axios Dependency in Jira Service Management Data Center | CVE-2026-42043 | 10/10 Krytyczna |
| Injection org.apache.tomcat:tomcat-coyote Dependency in Jira Service Management Data Center | CVE-2026-41293 | 9.8/10 Krytyczna |
| Authentication Bypass org.apache.tomcat:tomcat-catalina Dependency in Jira Service Management Data Center | CVE-2026-43512 | 9.8/10 Krytyczna |
| HTTP Request Smuggling io.netty:netty-codec-http Dependency in Jira Service Management Data Center | CVE-2026-42584 | 9.1/10 Krytyczna |
| Improper Authorization org.apache.tomcat:tomcat-catalina Dependency in Jira Service Management Data Center | CVE-2026-43515 | 9.1/10 Krytyczna |
| Injection axios Dependency in Jira Service Management Data Center | CVE-2026-42264 | 9.1/10 Krytyczna |
| DoS (Denial of Service) io.netty:netty-codec-http2 Dependency in Jira Service Management Data Center | CVE-2026-33871 | 8.7/10 Wysoka |
| RCE (Remote Code Execution) react-router Dependency in Jira Service Management Data Center | CVE-2026-42211 | 8.1/10 Wysoka |
| DoS (Denial of Service) io.netty:netty-codec Dependency in Jira Service Management Data Center | CVE-2026-42587 | 7.5/10 Wysoka |
| XSS (Cross Site Scripting) turbo-stream Dependency in Jira Service Management Data Center | CVE-2026-34077 | 7.5/10 Wysoka |
| DoS (Denial of Service) minimatch Dependency in Jira Service Management Data Center | CVE-2026-27903 | 7.5/10 Wysoka |
| HTTP Request Smuggling io.netty:netty-codec-http Dependency in Jira Service Management Data Center | CVE-2026-42585 | 7.5/10 Wysoka |
| Security Misconfiguration org.apache.tomcat:tomcat-catalina Dependency in Jira Service Management Data Center | CVE-2026-34486 | 7.5/10 Wysoka |
| DoS (Denial of Service) org.apache.tomcat:tomcat-catalina Dependency in Jira Service Management Data Center | CVE-2026-41284 | 7.5/10 Wysoka |
| DoS (Denial of Service) minimatch Dependency in Jira Service Management Data Center | CVE-2026-27904 | 7.5/10 Wysoka |
| DoS (Denial of Service) io.netty:netty-codec Dependency in Jira Service Management Data Center | CVE-2026-42583 | 7.5/10 Wysoka |
| SSRF (Server-Side Request Forgery) axios Dependency in Jira Service Management Data Center | CVE-2026-42038 | 7.5/10 Wysoka |
| Business Logic Vulnerability Apache Tomcat Dependency in Jira Service Management Data Center | CVE-2026-43513 | 7.5/10 Wysoka |
| DoS (Denial of Service) nth-check Dependency in Jira Service Management Data Center | CVE-2021-3803 | 7.5/10 Wysoka |
| DoS (Denial of Service) react-router Dependency in Jira Service Management Data Center | CVE-2026-42342 | 7.5/10 Wysoka |
| Cryptographic Failure org.apache.tomcat:tomcat-catalina Dependency in Jira Service Management Data Center | CVE-2026-29129 | 7.5/10 Wysoka |
| HTTP Request Smuggling io.netty:netty-codec-http Dependency in Jira Service Management Data Center | CVE-2026-33870 | 7.5/10 Wysoka |
| Information Disclosure org.apache.tomcat:tomcat-catalina Dependency in Jira Service Management Data Center | CVE-2026-34487 | 7.5/10 Wysoka |
| Injection axios Dependency in Jira Service Management Data Center | CVE-2026-42035 | 7.4/10 Wysoka |
| Injection axios Dependency in Jira Service Management Data Center | CVE-2026-42033 | 7.4/10 Wysoka |
| Information Disclosure org.apache.tomcat:tomcat-websocket Dependency in Jira Service Management Data Center and Server | CVE-2026-42498 | 7.3/10 Wysoka |
| RCE (Remote Code Execution) axios Dependency in Jira Service Management Data Center | CVE-2026-44495 | 7/10 Wysoka |