Atlassian third-party dependency patches (multiple vulnerabilities)
Security Patch Release
Summary
Hide ▲
Show ▼
Atlassian released fresh security updates for Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, and Jira after finding 10 critical and 162 high-severity issues in shared third-party dependencies. The release addresses about 109 unique CVEs and reduces exposure to RCE, DoS, information theft, MitM, authentication bypass, and SSRF across multiple products.
Related Happenings
Atlassian third-party dependency security bulletin
Security Patch Release
H score26
First: 20.08.2026 15:24
Last: 20.08.2026 15:24
Sources 1
How related:
On Tuesday, Atlassian published a Security Bulletin detailing 10 critical- and 162 high-severity issues in third-party dependencies, patched with fresh security updates for Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, and Jira.
About this happening:
Atlassian released a Security Bulletin with fresh updates for Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, and Jira to address 10 critical and 162 hig...
Atlassian third-party dependency security bulletin
Security Patch ReleaseHow related: On Tuesday, Atlassian published a Security Bulletin detailing 10 critical- and 162 high-severity issues in third-party dependencies, patched with fresh security updates for Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, and Jira.
About this happening: Atlassian released a Security Bulletin with fresh updates for Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, and Jira to address 10 critical and 162 hig...
Timeline
-
20.08.2026 15:24 2 articles · 2h ago
Atlassian patches third-party dependency vulnerabilities across Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, and Jira
Initial DisclosureAtlassian published a Security Bulletin on Tuesday that detailed 10 critical- and 162 high-severity issues in third-party dependencies and rolled out fresh security updates for Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, and Jira. Because the vulnerable libraries are used across multiple products, many of the fixes apply to more than one product and address risks including remote code execution, denial-of-service, information theft, man-in-the-middle, authentication bypass, and server-side request forgery.
Show sources
- Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities — www.securityweek.com — 20.08.2026 15:24
- Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities — www.securityweek.com — 20.08.2026 15:24