Atlassian Jira and Confluence
Everything ChangeIntel collected about Atlassian Jira and Confluence from 2 sources, on one timeline.
Watching for changes since 26 Sep 2026. Revisions the vendor made before then were not observed, which does not mean there were none.
Atlassian Jira and Confluence timeline
8 weeks back, 6 ahead · mark size shows importance, not volume- Release or post
- Known issue
- Out-of-band, exploited, or incident
- Revised by its source
- Deadline
SecurityMSRC · CISA KEV · security news
- Tue 18 Aug · Security advisory: Confluence Data Center: Injection minimist Dependency (CVE-2021-44906) and 45 more (The vendor rates it critical)
- Tue 15 Sep · Security advisory: Jira Software Data Center: Injection json5 Dependency (CVE-2022-46175) and 52 more (The vendor rates it high)
- Mon 5 Oct · Security advisory: Jira Service Management Data Center: Arbitrary File Access (CVE-2026-21589) (The vendor rates it critical)
54 changes54 worth a look
Atlassian Jira and Confluence changelog
RSSOctober 2026
- Issues and security Security advisory · Jira Service Management Data Center: Arbitrary File Access (CVE-2026-21589)
September 2026
- Issues and security Security advisory · Jira Software Data Center: Injection json5 Dependency (CVE-2022-46175)
- Issues and security Security advisory · Jira Software Data Center: BASM (Broken Authentication & Session Management) Bouncy Castle Dependency (CVE-2026-12802)
- Issues and security Security advisory · Jira Software Data Center: BASM (Broken Authentication & Session Management) Bouncy Castle Dependency (CVE-2026-12803)
- Issues and security Security advisory · Jira Software Data Center and Server: BASM (Broken Authentication & Session Management) Bouncy Castle Dependency (CVE-2026-12816)
- Issues and security Security advisory · Jira Software Data Center and Server: DoS (Denial of Service) Apache Tomcat Dependency (CVE-2026-13506)
- Issues and security Security advisory · Jira Software Data Center: Injection fast-uri Dependency (CVE-2026-13676)
- Issues and security Security advisory · Jira Software Data Center: DoS (Denial of Service) brace-expansion Dependency (CVE-2026-14257)
- Issues and security Security advisory · Jira Software Data Center: RCE (Remote Code Execution) org.bouncycastle:bcprov-lts8on Dependency (CVE-2026-14682)
- Issues and security Security advisory · Jira Software Data Center: Injection fast-uri Dependency (CVE-2026-16221)
- Issues and security Security advisory · Jira Software Data Center: Injection fast-uri Dependency (CVE-2026-18446)
- Issues and security Security advisory · Confluence Data Center: Improper Authorization (CVE-2026-21586)
- Issues and security Security advisory · Jira Service Management Data Center: Improper Authorization (CVE-2026-21587)
- Issues and security Security advisory · Confluence Data Center: DoS (Denial of Service) (CVE-2026-21588)
- Issues and security Security advisory · Jira Software Data Center: RCE (Remote Code Execution) @babel/plugin-transform-modules-systemjs Dependency (CVE-2026-44728)
- Issues and security Security advisory · Confluence Data Center: MITM (Man-in-the-Middle) Netty Dependency (CVE-2026-45674)
- Issues and security Security advisory · Confluence Data Center: MITM (Man-in-the-Middle) Netty Dependency (CVE-2026-47691)
- Issues and security Security advisory · Jira Software Data Center: DOM-based XSS tinymce Dependency (CVE-2026-47759)
- Issues and security Security advisory · Jira Software Data Center: DOM-based XSS tinymce Dependency (CVE-2026-47761)
- Issues and security Security advisory · Jira Software Data Center: DOM-based XSS tinymce Dependency (CVE-2026-47762)
- Issues and security Security advisory · Jira Service Management Data Center: DoS (Denial of Service) linkify-it Dependency (CVE-2026-48801)
- Issues and security Security advisory · Jira Software Data Center: Apache Tomcat: Bad ornext processing in RewriteValve (CVE-2026-53404)
- Issues and security Security advisory · Jira Software Data Center and Server: BASM (Broken Authentication & Session Management) Apache Tomcat Dependency (CVE-2026-53434)
- Issues and security Security advisory · Crucible Data Center and Server: DoS (Denial of Service) at org.apache.httpcomponents.core5:httpcore5-h2 Dependency (CVE-2026-54428)
- Issues and security Security advisory · Jira Software Data Center: DoS (Denial of Service) com.fasterxml.jackson.core:jackson-databind Dependency (CVE-2026-54512)
- Issues and security Security advisory · Jira Software Data Center: jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (CVE-2026-54513)
- Issues and security Security advisory · Crucible Server: DoS (Denial of Service) at com.mchange:mchange-commons-java Dependency (CVE-2026-55153)
- Issues and security Security advisory · Jira Software Data Center and Server: BASM (Broken Authentication & Session Management) Apache Tomcat Dependency (CVE-2026-55276)
- Issues and security Security advisory · Jira Software Data Center: DoS (Denial of Service) Apache Tomcat Dependency (CVE-2026-58059)
- Issues and security Security advisory · Jira Software Data Center: RCE (Remote Code Execution) org.bouncycastle:bcprov-lts8on Dependency (CVE-2026-58060)
- Issues and security Security advisory · Jira Software Data Center: BASM (Broken Authentication & Session Management) Bouncy Castle Dependency (CVE-2026-59639)
- Issues and security Security advisory · Jira Software Data Center and Server: BASM (Broken Authentication & Session Management) Bouncy Castle Dependency (CVE-2026-59642)
- Issues and security Security advisory · Jira Software Data Center: Injection org.bouncycastle:bcprov-lts8on Dependency (CVE-2026-59650)
- Issues and security Security advisory · Jira Software Data Center: DoS (Denial of Service) js-yaml Dependency (CVE-2026-59869)
- Issues and security Security advisory · Jira Software Data Center: DoS (Denial of Service) immutable Dependency (CVE-2026-59879)
- Issues and security Security advisory · Jira Software Data Center: DoS (Denial of Service) immutable Dependency (CVE-2026-59880)
- Issues and security Security advisory · Jira Service Management Data Center: DoS (Denial of Service) linkify-it Dependency (CVE-2026-59887)
- Issues and security Security advisory · Crowd Data Center and Server: DoS (Denial of Service) nanoid Dependency (CVE-2026-67213)
- Issues and security Security advisory · Jira Software Data Center and Server: DoS (Denial of Service) nanoid Dependency (CVE-2026-67214)
- Issues and security Security advisory · Jira Software Data Center: Information Disclosure axios Dependency (CVE-2026-67320)
- Issues and security Security advisory · Jira Software Data Center: DoS (Denial of Service) org.apache.tomcat:tomcat-coyote Dependency (CVE-2026-68763)
- Issues and security Security advisory · Jira Software Data Center: DoS (Denial of Service) brace-expansion Dependency (CVE-2026-69152)
- Issues and security Security advisory · Jira Software Data Center: CSRF (Cross-Site Request Forgery) nanoid Dependency (CVE-2026-73086)
- Issues and security Security advisory · Jira Software Data Center: DoS (Denial of Service) browserslist Dependency (CVE-2026-73088)
- Issues and security Security advisory · Jira Software Data Center: DoS (Denial of Service) browserslist Dependency (CVE-2026-73089)
- Issues and security Security advisory · Jira Software Data Center: DoS (Denial of Service) io.netty:netty-codec Dependency (CVE-2026-73507)
- Issues and security Security advisory · Jira Software Data Center: DoS (Denial of Service) node-tar dependency tar Dependency (CVE-2026-73566)
- Issues and security Security advisory · Jira Software Data Center: File Inclusion postcss Dependency (CVE-2026-73646)
- Issues and security Security advisory · Crucible Server: DoS (Denial of Service) at org.jsoup:jsoup Dependency (CVE-2026-75140)
- Issues and security Security advisory · Bamboo Data Center: RCE (Remote Code Execution) at io.netty dependency (CVE-2026-75595)
- Issues and security Security advisory · Jira Software Data Center: SSRF (Server-Side Request Forgery) fast-uri Dependency (CVE-2026-75899)
- Issues and security Security advisory · Jira Software Data Center: SSRF (Server-Side Request Forgery) fast-uri Dependency (CVE-2026-75975)
- Issues and security Security advisory · Jira Software Data Center: SSRF (Server-Side Request Forgery) fast-uri Dependency (CVE-2026-76172)
- Issues and security Security advisory · Jira Software Data Center: BASM (Broken Authentication & Session Management) org.bouncycastle:bcprov-jdk18on Dependency (CVE-2026-8763)
August 2026
- Issues and security Security advisory · Confluence Data Center: Injection minimist Dependency (CVE-2021-44906)
- Issues and security Security advisory · Jira Software Data Center: Arbitrary code execution (RCE) @babel/traverse dependency (CVE-2023-45133)
- Issues and security Security advisory · Crowd Data Center: SQLi (SQL Injection) org.hibernate:hibernate-core-jakarta Dependency (CVE-2026-0603)
- Issues and security Security advisory · Crucible Server: BASM (Broken Authentication & Session Management) org.eclipse.jetty:jetty-security Dependency (CVE-2026-10050)
- Issues and security Security advisory · Jira Software Data Center: RCE (Remote Code Execution) form-data Dependency (CVE-2026-12143)
- Issues and security Security advisory · Jira Software Data Center: DoS (Denial of Service) undici Dependency (CVE-2026-12151)
- Issues and security Security advisory · Jira Software Data Center: DoS (Denial of Service) brace-expansion Dependency (CVE-2026-13149)
- Issues and security Security advisory · Crucible Server: Inconsistent Interpretation of HTTP Requests at org.eclipse.jetty:jetty-http dependency (CVE-2026-2332)
- Issues and security Security advisory · Jira Software Data Center: Injection org.apache.tomcat:tomcat-coyote-ffm Dependency (CVE-2026-24734)
- Issues and security Security advisory · Crowd Data Center: DoS (Denial of Service) underscore Dependency (CVE-2026-27601)
- Issues and security Security advisory · Jira Software Data Center: File Inclusion rollup Dependency (CVE-2026-27606)
- Issues and security Security advisory · Bitbucket Data Center: DoS (Denial of Service) org.bouncycastle:bcpg-lts8on Dependency (CVE-2026-3505)
- Issues and security Security advisory · Crowd Data Center: DoS (Denial of Service) io.micrometer:micrometer-core Dependency (CVE-2026-40984)
- Issues and security Security advisory · Jira Software Data Center: DoS (Denial of Service) org.springframework:spring-webmvc Dependency (CVE-2026-41842)
- Issues and security Security advisory · Jira Software Data Center: DOM-based XSS org.springframework:spring-webmvc Dependency (CVE-2026-41845)
- Issues and security Security advisory · Crowd Data Center: DoS (Denial of Service) org.springframework:spring-expression Dependency (CVE-2026-41850)
- Issues and security Security advisory · Crowd Data Center: DoS (Denial of Service) org.springframework:spring-expression Dependency (CVE-2026-41851)
- Issues and security Security advisory · Bamboo Data Center: RCE (Remote Code Execution) uuid Dependency (CVE-2026-41907)
- Issues and security Security advisory · Crowd Data Center: Injection axios Dependency (CVE-2026-42041)
- Issues and security Security advisory · Jira Software Data Center: DoS (Denial of Service) io.netty:netty-codec Dependency (CVE-2026-42587)
- Issues and security Security advisory · Jira Software Data Center: Improper Authorization io.netty:netty-handler Dependency (CVE-2026-44249)
- Issues and security Security advisory · Jira Software Data Center: Information Disclosure axios Dependency (CVE-2026-44486)
- Issues and security Security advisory · Jira Software Data Center: Information Disclosure axios Dependency (CVE-2026-44487)
- Issues and security Security advisory · Jira Software Data Center: DoS (Denial of Service) axios Dependency (CVE-2026-44488)
- Issues and security Security advisory · Jira Service Management Data Center: Injection axios Dependency (CVE-2026-44490)
- Issues and security Security advisory · Jira Software Data Center: SSRF (Server-Side Request Forgery) axios Dependency (CVE-2026-44492)
- Issues and security Security advisory · Jira Software Data Center: Injection axios Dependency (CVE-2026-44494)
- Issues and security Security advisory · Jira Service Management Data Center: DoS (Denial of Service) axios Dependency (CVE-2026-44496)
- Issues and security Security advisory · Jira Software Data Center: DoS (Denial of Service) io.netty:netty-handler Dependency (CVE-2026-45416)
- Issues and security Security advisory · Crowd Data Center: Information Disclosure postcss Dependency (CVE-2026-45623)
- Issues and security Security advisory · Jira Software Data Center: Injection js-cookie Dependency (CVE-2026-46625)
- Issues and security Security advisory · Jira Software Data Center: BASM (Broken Authentication & Session Management) org.springframework.security:spring-security-web Dependency (CVE-2026-47838)
- Issues and security Security advisory · Jira Software Data Center: RCE (Remote Code Execution) at lodash dependency (CVE-2026-4800)
- Issues and security Security advisory · Jira Software Data Center: DoS (Denial of Service) io.netty:netty-codec-http2 Dependency (CVE-2026-48043)
- Issues and security Security advisory · Jira Software Data Center: MITM (Man-in-the-Middle) io.netty:netty-handler Dependency (CVE-2026-50010)
- Issues and security Security advisory · Jira Software Data Center: MITM (Man-in-the-Middle) org.postgresql:postgresql Dependency (CVE-2026-54291)
- Issues and security Security advisory · Jira Software Data Center: DoS (Denial of Service) react-router Dependency (CVE-2026-55685)
- Issues and security Security advisory · Jira Software Data Center: DoS (Denial of Service) io.netty:netty-codec-http Dependency (CVE-2026-55831)
- Issues and security Security advisory · Jira Software Data Center: DoS (Denial of Service) io.netty:netty-codec-http Dependency (CVE-2026-55833)
- Issues and security Security advisory · Jira Software Data Center: DoS (Denial of Service) io.netty:netty-codec-http Dependency (CVE-2026-56745)
- Issues and security Security advisory · Jira Software Data Center: DoS (Denial of Service) io.netty:netty-codec-http2 Dependency (CVE-2026-56819)
- Issues and security Security advisory · Jira Software Data Center: DoS (Denial of Service) tar Dependency (CVE-2026-59871)
- Issues and security Security advisory · Jira Software Data Center: DoS (Denial of Service) node-tar dependency (CVE-2026-59873)
- Issues and security Security advisory · Jira Software Data Center: DoS (Denial of Service) tar Dependency (CVE-2026-59874)
- Issues and security Security advisory · Jira Software Data Center: DoS (Denial of Service) io.netty:netty-codec Dependency (CVE-2026-59901)
- Issues and security Security advisory · Jira Software Data Center: SSRF (Server-Side Request Forgery) ip-address Dependency (CVE-2026-69192)
Sorted from how each source classifies its records: what's-new pages, releases, documentation changes, notices, roadmap items, and network changes. A kind is a reading aid, not Microsoft's own category.
Nothing about Atlassian Jira and Confluence yet in: threads across sources, revisions by the vendor, open known issues, dates in the next 12 months, roadmap items in progress, versions.