Atlassian third-party dependency security bulletin
Security Patch Release
Summary
Hide ▲
Show ▼
Atlassian released a Security Bulletin with fresh updates for Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, and Jira to address 10 critical and 162 high-severity third-party dependency issues. The bundled fixes cover about 109 unique CVEs and reduce exposure to RCE, DoS, information theft, MitM, authentication bypass, and SSRF. The bulletin makes the patch cycle relevant across multiple Atlassian product lines because shared libraries spread the defects beyond a single application.
Related Happenings
Atlassian third-party dependency patches (multiple vulnerabilities)
Security Patch Release
H score26
First: 20.08.2026 15:24
Last: 20.08.2026 15:24
Sources 1
How related:
On Tuesday, Atlassian published a Security Bulletin detailing 10 critical- and 162 high-severity issues in third-party dependencies, patched with fresh security updates for Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, and Jira.
About this happening:
Atlassian released fresh security updates for Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, and Jira after finding 10 critical and 162 high-severity issu...
Atlassian third-party dependency patches (multiple vulnerabilities)
Security Patch ReleaseHow related: On Tuesday, Atlassian published a Security Bulletin detailing 10 critical- and 162 high-severity issues in third-party dependencies, patched with fresh security updates for Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, and Jira.
About this happening: Atlassian released fresh security updates for Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, and Jira after finding 10 critical and 162 high-severity issu...
Timeline
-
20.08.2026 15:24 2 articles · 2h ago
Atlassian publishes security bulletin for third-party dependency flaws
Initial DisclosureAtlassian published a Security Bulletin on Tuesday covering 10 critical and 162 high-severity issues in third-party dependencies across Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, and Jira. The fresh security updates address approximately 109 unique CVEs, and many defects affect multiple products because the vulnerable libraries are shared.
Show sources
- Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities — www.securityweek.com — 20.08.2026 15:24
- Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities — www.securityweek.com — 20.08.2026 15:24
-
20.08.2026 15:24 1 articles · 2h ago
Splunk releases fixes for 150 vulnerabilities across Enterprise, SOAR, and Universal Forwarder
Mitigation Patch UpdateSplunk announced fixes on Wednesday for at least 150 vulnerabilities across Splunk Enterprise, SOAR, Universal Forwarder, and associated apps and plugins. The release includes Splunk Enterprise versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14, updates for Splunk Apps and Add-ons and Splunk SOAR, Enterprise Security version 8.6.1, SOAR Connectors, and a Universal Forwarder update that addresses OpenSSL weaknesses.
Show sources
- Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities — www.securityweek.com — 20.08.2026 15:24