Atlassian published security advisory AV26-731 covering multiple vulnerabilities, including some rated critical, across a broad set of products used in data center, server, and desktop environments. Affected product lines named in follow-on notices include Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, Jira, Jira Service Management, and Sourcetree for Mac and Windows, and government guidance urged administrators to review the advisories and apply vendor updates.
One of the disclosed issues, CVE-2026-21579, is a high-severity information disclosure flaw in Atlassian Confluence Data Center with a CVSS 4.0 score of 8.2. Atlassian said the vulnerability can be exploited remotely by an unauthenticated attacker to access sensitive information, affects multiple Confluence Data Center release lines, and is fixed in supported versions including 9.2.22 or later and 10.2.14 or later; customers were advised to upgrade to the latest or patched supported releases.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published a notice about Atlassian advisory AV26-731 covering multiple vulnerabilities, including some rated critical, across several Atlassian products. The notice urged administrators to review the advisories and apply the necessary updates.
Atlassian disclosed CVE-2026-21579, a high-severity information disclosure vulnerability in Confluence Data Center that can allow unauthenticated remote attackers to view sensitive information. Atlassian said the issue affected multiple release lines and recommended upgrading to fixed supported versions including 9.2.22+ and 10.2.14+.
Atlassian published Jira issue CONFSERVER-104340 describing a high-severity information disclosure vulnerability in Confluence Data Center with CVSS 8.2. The issue affected versions across multiple release lines and advised upgrading to fixed releases including 9.2.22+ and 10.2.14+.
Atlassian published the referenced security advisories page that serves as the vendor source for the disclosed issues.
Atlassian released security updates for Bamboo Data Center and Server, Confluence Data Center and Server, Jira Data Center and Server, and Jira Service Management Data Center and Server to fix 30 vulnerabilities. The bulletin highlighted Bamboo flaws CVE-2024-21687 and CVE-2024-22262 among the most serious issues and provided fixed versions for affected product lines.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecvefeed.io
Open sourcejira.atlassian.com
Open sourceatlassian.com
Open sourcecsirt.sk
Open sourceconfluence.atlassian.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.