21 lipca 2026 r. firma Atlassian opublikowała ostrzeżenie dotyczące bezpieczeństwa w celu usunięcia luk w zabezpieczeniach, w tym kilku krytycznych, w następujących produktach:

  • Bamboo Data Center i Server – wiele wersji
  • Bitbucket Data Center i Server – wiele wersji
  • Confluence Data Center i Server – wiele wersji
  • Crowd Data Center i Server – wiele wersji
  • Fisheye/Crucible – wersje od 4.9.0 do 4.9.11
  • Jira Data Center i Server – wiele wersji
  • Jira Service Management Data Center i Server – wiele wersji
  • Sourcetree dla komputerów Mac – wszystkie wersje od 3.4.11 do 3.4.12
  • Sourcetree dla systemu Windows – wszystkie wersje od 3.4.11 do 3.4.12
ProduktPodatna wersjaPatchLink/OpisNumer CVEKrytyczność
Bamboo Data Center and Server12.1.0 to 12.1.8 (LTS) 12.0.0 to 12.0.2 11.0.0 to 11.0.8 10.2.0 to 10.2.20 (LTS) 10.1.0 to 10.1.1 10.0.0 to 10.0.312.1.9 (LTS) recommended Data Center Only 10.2.21 (LTS) Data Center OnlyRCE (Remote Code Execution) at lodash dependency in Bamboo Data CenterCVE-2026-48009.8 Krytyczna
RCE (Remote Code Execution) at Apache ActiveMQ dependency in Bamboo Data CenterCVE-2026-455058.8 Wysoka
Injection at axios dependency in Bamboo Data CenterCVE-2026-444948.7 Wysoka
Injection at axios dependency in Bamboo Data CenterCVE-2026-444908.2 Wysoka
RCE (Remote Code Execution) at Apache ActiveMQ dependency in Bamboo Data CenterCVE-2026-425888.1 Wysoka
Improper Authorization netty Dependency in Bamboo Data CenterCVE-2026-442498.1 Wysoka
Information Disclosure at Apache Tomcat dependency in Bamboo Data CenterCVE-2026-291467.5 Wysoka
DoS (Denial of Service) at netty-handler Dependency in Bamboo Data CenterCVE-2026-454167.5 Wysoka
Improper Verification of Cryptographic Signature at netty-handler dependency in Bamboo Data CenterCVE-2026-500107.5 Wysoka
RCE (Remote Code Execution) at axios dependency in Bamboo Data CenterCVE-2026-444957 Wysoka
Bitbucket Data Center and Server10.3.0 to 10.3.1 10.2.0 to 10.2.4 (LTS) 10.1.1 to 10.1.5 10.0.0 to 10.0.2 9.6.0 to 9.6.5 9.5.0 to 9.5.2 9.4.0 to 9.4.21 (LTS) 9.3.0 to 9.3.2 9.2.0 to 9.2.1 9.1.0 to 9.1.1 9.0.110.3.2 Data Center Only 10.2.5 (LTS) recommended Data Center Only 9.4.22 (LTS) Data Center OnlyRCE (Remote Code Execution) at 'getobject’ version in Bitbucket Data CenterCVE-2020-282829.8 Krytyczna
Cryptographic Failure org.bouncycastle:bcprov-jdk18on Dependency in Bitbucket Data CenterCVE-2026-55988.9 Wysoka
DoS (Denial of Service) with Netty Dependency in Bitbucket Data CenterCVE-2026-338718.7 Wysoka
Injection in Bitbucket Data CenterCVE-2026-444948.7 Wysoka
Race condition in Bitbucket Data CenterCVE-2026-355548.7 Wysoka
SSRF (Server-Side Request Forgery) in Bitbucket Data CenterCVE-2026-444928.6 Wysoka
Injection axios Dependency in Bitbucket Data CenterCVE-2026-420418.2 Wysoka
Injection in Bitbucket Data CenterCVE-2026-444908.2 Wysoka
BASM (Broken Authentication & Session Management) org.springframework.boot:spring-boot-actuator-autoconfigure Dependency in Bitbucket Data CenterCVE-2026-227318.2 Wysoka
Information Disclosure in Bitbucket Data CenterCVE-2026-444878.2 Wysoka
BASM (Broken Authentication & Session Management) in Bitbucket Data CenterCVE-2026-478388.1 Wysoka
HTTP Request Smuggling io.netty:netty-codec-http Dependency in Bitbucket Data CenterCVE-2026-338707.5 Wysoka
Injection in Bitbucket Data CenterCVE-2026-63227.5 Wysoka
File Inclusion in Bitbucket Data CenterCVE-2026-63217.5 Wysoka
DoS (Denial of Service) in Bitbucket Data CenterCVE-2026-444887.5 Wysoka
HTTP Request Smuggling io.netty:netty-codec-http Dependency in Bitbucket Data CenterCVE-2026-425857.5 Wysoka
DoS (Denial of Service) in Bitbucket Data CenterCVE-2026-444967.5 Wysoka
RCE (Remote Code Execution) in Bitbucket Data CenterCVE-2026-457367.5 Wysoka
Injection in Bitbucket Data CenterCVE-2026-466257.5 Wysoka
DoS (Denial of Service) in Bitbucket Data CenterCVE-2016-105407.5 Wysoka
DoS (Denial of Service) in Bitbucket Data CenterCVE-2026-480437.5 Wysoka
Information Disclosure in Bitbucket Data CenterCVE-2026-444867.5 Wysoka
RCE (Remote Code Execution) in Bitbucket Data CenterCVE-2021-233587.2 Wysoka
RCE (Remote Code Execution) grunt Dependency in Bitbucket Data CenterCVE-2020-77297.1 Wysoka
RCE (Remote Code Execution) in Bitbucket Data CenterCVE-2026-444957 Wysoka
Race condition in Bitbucket Data CenterCVE-2022-15377 Wysoka
Confluence Data Center and Server10.2.0 to 10.2.13 (LTS) 10.1.0 to 10.1.2 10.0.2 to 10.0.3 9.5.1 to 9.5.4 9.4.0 to 9.4.1 9.3.1 to 9.3.2 9.2.0 to 9.2.21 (LTS) 9.1.0 to 9.1.1 9.0.1 to 9.0.3 8.9.5 to 8.9.8 8.5.14 to 8.5.31 (LTS) 7.19.26 to 7.19.30 (LTS)10.2.14 (LTS) recommended Data Center Only 9.2.22 (LTS) Data Center OnlySSRF (Server-Side Request Forgery) axios Dependency in Confluence Data CenterCVE-2026-4204310 Krytyczna
SSRF (Server-Side Request Forgery) axios Dependency in Confluence Data CenterCVE-2025-627189.9 Krytyczna
RCE (Remote Code Execution) at lodash dependency in Confluence Data CenterCVE-2026-48009.8 Krytyczna
HTTP Request Smuggling org.eclipse.jetty:jetty-http Dependency in Confluence Data CenterCVE-2026-23329.1 Krytyczna
Prototype Pollution Axios Dependency in Confluence Data CenterCVE-2026-422649.1 Krytyczna
SSRF (Server-Side Request Forgery) Axios Dependency in Confluence Data CenterCVE-2026-401759 Krytyczna
Injection axios Dependency in Confluence Data CenterCVE-2026-444948.7 Wysoka
RCE (Remote Code Execution) form-data Dependency in Confluence Data CenterCVE-2026-121438.7 Wysoka
SSRF (Server-Side Request Forgery) axios Dependency in Confluence Data CenterCVE-2026-444928.6 Wysoka
Information Disclosure axios Dependency in Confluence Data CenterCVE-2026-444878.2 Wysoka
File Inclusion node-tar Dependency in Confluence Data CenterCVE-2026-318028.2 Wysoka
Injection axios Dependency in Confluence Data CenterCVE-2026-444908.2 Wysoka
Information Disclosure in Confluence Data CenterCVE-2026-215798.2 Wysoka
Injection axios Dependency in Confluence Data CenterCVE-2026-420418.2 Wysoka
DoS (Denial of Service) serialize-javascript Dependency in Confluence Data CenterCVE-2026-340437.5 Wysoka
DoS (Denial of Service) netty Dependency in Confluence Data CenterCVE-2026-425837.5 Wysoka
DoS (Denial of Service) axios Dependency in Confluence Data CenterCVE-2026-444967.5 Wysoka
DoS (Denial of Service) axios Dependency in Confluence Data CenterCVE-2026-444887.5 Wysoka
File Inclusion fast-uri Dependency in Confluence Data CenterCVE-2026-63217.5 Wysoka
Injection fast-uri Dependency in Confluence Data CenterCVE-2026-63227.5 Wysoka
Injection js-cookie Dependency in Confluence Data CenterCVE-2026-466257.5 Wysoka
DoS (Denial of Service) picomatch Dependency in Confluence Data CenterCVE-2026-336717.5 Wysoka
Information Disclosure axios Dependency in Confluence Data CenterCVE-2026-444867.5 Wysoka
DoS (Denial of Service) in Confluence Data CenterCVE-2026-487797.5 Wysoka
DoS (Denial of Service) io.netty:netty-codec-http Dependency in Confluence Data Center and ServerCVE-2026-425877.5 Wysoka
Injection axios Dependency in Confluence Data CenterCVE-2026-420357.4 Wysoka
Injection axios Dependency in Confluence Data CenterCVE-2026-420337.4 Wysoka
DoS (Denial of Service) in Confluence Data CenterCVE-2026-215777.1 Wysoka
RCE (Remote Code Execution) axios Dependency in Confluence Data CenterCVE-2026-444957 Wysoka
Injection logback-core Dependency in Confluence Data CenterCVE-2025-112267 Wysoka
Crowd Data Center and Server7.2.0 7.1.0 to 7.1.5 6.3.1 to 6.3.6 6.2.0 to 6.2.6 6.1.3 to 6.1.7 6.0.1 to 6.0.10 5.3.3 to 5.3.87.2.1 (LTS) recommended Data Center OnlyRCE (Remote Code Execution) c3p0 Dependency in Crowd Data CenterCVE-2026-278308.9 Wysoka
Fisheye/Crucible4.9.0 to 4.9.114.9.12 recommendedRCE (Remote Code Execution) com.google.protobuf:protobuf-java Dependency in Crucible ServerCVE-2024-72548.7 Wysoka
DoS (Denial of Service) com.google.protobuf:protobuf-java Dependency in Crucible ServerCVE-2022-35107.5 Wysoka
DoS (Denial of Service) com.google.protobuf:protobuf-java Dependency in Crucible ServerCVE-2022-35097.5 Wysoka
DoS (Denial of Service) com.google.protobuf:protobuf-java Dependency in Crucible ServerCVE-2021-225697.5 Wysoka
Jira Data Center and Server11.3.0 to 11.3.7 (LTS) 11.2.0 to 11.2.1 11.1.0 to 11.1.1 11.0.0 to 11.0.1 10.7.1 to 10.7.4 10.6.0 to 10.6.1 10.5.0 to 10.5.1 10.4.0 to 10.4.1 10.3.0 to 10.3.22 (LTS) 10.2.0 to 10.2.1 10.1.1 to 10.1.2 10.0.0 to 10.0.1 9.17.2 to 9.17.5 9.12.12 to 9.12.36 (LTS)11.3.8 (LTS) recommended Data Center Only 10.3.23 (LTS) Data Center OnlyPrototype pollution vulnerability parseQuery dependency in Jira Software Data CenterCVE-2022-376019.8 Krytyczna
HTTP Request Smuggling io.netty:netty-codec-http Dependency in Jira Software Data CenterCVE-2026-425819.8 Krytyczna
Cryptographic Failure org.bouncycastle:bcprov Dependency in Jira Software Data CenterCVE-2025-148139.3 Krytyczna
BASM (Broken Authentication & Session Management) in Jira Software Data CenterCVE-2026-291459.1 Krytyczna
Prototype Pollution „Gadget” Axios Dependency in Jira Software Data CenterCVE-2026-420449.1 Krytyczna
Injection Immutable.js Dependency in Jira Software Data CenterCVE-2026-290638.7 Wysoka
File Inclusion node-tmp Dependency in Jira Software Data CenterCVE-2026-447057.7 Wysoka
Information Disclosure Apache Tomcat Dependency in Jira Software Data CenterCVE-2026-291467.5 Wysoka
DoS (Denial of Service) loader-utils Dependency in Jira Software Data CenterCVE-2022-376037.5 Wysoka
DoS (Denial of Service) loader-utils Dependency in Jira Software Data CenterCVE-2022-375997.5 Wysoka
File Inclusion fast-uri Dependency in Jira Software Data CenterCVE-2026-63217.5 Wysoka
Injection fast-uri Dependency in Jira Software Data CenterCVE-2026-63227.5 Wysoka
DoS (Denial of Service) pgjdbc Dependency in Jira Software Data CenterCVE-2026-421987.5 Wysoka
DoS (Denial of Service) ajv Dependency in Jira Software Data CenterCVE-2025-698737.5 Wysoka
Jira Service Management Data Center and Server11.3.0 to 11.3.7 (LTS) 11.2.0 to 11.2.1 11.1.0 to 11.1.1 11.0.0 to 11.0.1 10.7.1 to 10.7.4 10.6.0 to 10.6.1 10.5.0 to 10.5.1 10.4.0 to 10.4.1 10.3.0 to 10.3.22 (LTS) 10.2.0 to 10.2.1 10.1.1 to 10.1.2 10.0.0 to 10.0.1 5.17.2 to 5.17.511.3.8 (LTS) recommended Data Center Only 10.3.23 (LTS) Data Center OnlyPrototype pollution vulnerability parseQuery dependency in Jira Software Data CenterCVE-2022-376019.8 Krytyczna
HTTP Request Smuggling io.netty:netty-codec-http Dependency in Jira Service Management Data CenterCVE-2026-425819.8 Krytyczna
Cryptographic Failure org.bouncycastle:bcprov Dependency in Jira Service Management Data CenterCVE-2025-148139.3 Krytyczna
BASM (Broken Authentication & Session Management) in Jira Service Management Data CenterCVE-2026-291459.1 Krytyczna
Prototype Pollution „Gadget” Axios Dependency in Jira Service Management Data CenterCVE-2026-420449.1 Krytyczna
Injection Immutable.js Dependency in Jira Service Management Data CenterCVE-2026-290638.7 Wysoka
BASM (Broken Authentication & Session Management) SubjectDnX509PrincipalExtractor Dependency in Jira Service Management Data CenterCVE-2026-478388.1 Wysoka
File Inclusion node-tmp Dependency in Jira Service Management Data CenterCVE-2026-447057.7 Wysoka
Information Disclosure Apache Tomcat Dependency in Jira Service Management Data CenterCVE-2026-291467.5 Wysoka
File Inclusion fast-uri Dependency in Jira Service Management Data CenterCVE-2026-63217.5 Wysoka
DoS (Denial of Service) ajv Dependency in Jira Service Management Data CenterCVE-2025-698737.5 Wysoka
DoS (Denial of Service) loader-utils Dependency in Jira Service Management Data CenterCVE-2022-375997.5 Wysoka
DoS (Denial of Service) loader-utils Dependency in Jira Service Management Data CenterCVE-2022-376037.5 Wysoka
DoS (Denial of Service) pgjdbc Dependency in Jira Service Management Data CenterCVE-2026-421987.5 Wysoka
Injection fast-uri Dependency in Jira Service Management Data CenterCVE-2026-63227.5 Wysoka
Sourcetree for MacAll versions from 3.4.11 to 3.4.12All versions from 3.4.13RCE (Remote Code Execution) in Sourcetree for Mac and Sourcetree for WindowsCVE-2026-215757.1 Wysoka
Sourcetree for WindowsAll versions from 3.4.11 to 3.4.12All versions from 3.4.13RCE (Remote Code Execution) in Sourcetree for Mac and Sourcetree for WindowsCVE-2026-215757.1 Wysoka