Atlassian disclosed a high-severity file inclusion vulnerability in Jira Software Data Center that affects versions 9.17.5 and 11.3.8. The flaw, tracked in Atlassian's advisory with a CVSS 4.0 score of 8.8, could allow an unauthenticated attacker to read local files or execute other files already present on the server, creating a significant risk for exposed Jira deployments.
Atlassian directed customers to upgrade to a fixed supported release, including Jira Software Data Center 11.3.10 or later in the 11.3 branch, or otherwise move to the latest available version. A separate Atlassian notice also states that Data Center products are scheduled to reach end of life in 2029 as the company shifts focus to cloud offerings, underscoring the need for organizations still running self-managed Jira environments to prioritize remediation and longer-term migration planning.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Atlassian published a vulnerability notice for a high-severity Jira Software Data Center file inclusion issue with a CVSS 4.0 score of 8.8. The company advised customers to upgrade to the latest version or move to a supported fixed release, including 11.3.10 or later for the 11.3 branch.
Atlassian states a high-severity file inclusion vulnerability affecting Jira Software Data Center was introduced in versions 9.17.5 and 11.3.8. The flaw can let an unauthenticated attacker read local files or execute another file already stored on the server.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.