LIVE · cybersecurity feed
Live wire
vendor

Atlassian

4 CVEs published in the last four months and 7 stories. Exploited flaws first.

Critical0
High3
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-215708.8bambooThis High severity RCE (Remote Code Execution) vulnerability was introduced in versions 9.6.0, 10.0.0, 10.1.0, 10.208d ago
CVE-2026-215848.1highbambooThis High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0,53d ago
CVE-2026-215758highsourcetreeThis High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Ma82d ago
CVE-2026-215797.5highconfluence data centerThis High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 982d ago

Filter the full tracker by Atlassian →

Our coverage of Atlassian

CVE-2026-21589critical

Exploitation attempts against critical Atlassian flaw have begun (CVE-2026-21589)

Exploitation attempts have begun against a critical arbitrary file access vulnerability, CVE-2026-21589, affecting multiple self-managed Atlassian Data Center products. The attempts were observed by threat intelligence vendor Previdian on Tuesday, just one day after Atlassian released patches and hours after security researchers published a technical analysis of the flaw.

vulnerabilitycritical

Atlassian Patches Critical Vulnerability Affecting 8 Products

Atlassian has released patches for a critical vulnerability impacting eight of its products. The flaw, if exploited, could allow unauthenticated attackers to gain access to specific files located within the web application's root directory. This type of access could potentially expose sensitive configuration or application data, depending on the contents of the accessible files.

CVE-2026-21589critical

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

A critical vulnerability has been reported in eight Atlassian Data Center products, enabling unauthenticated attackers to read known files within the web application root directory. The flaw, identified as CVE-2026-21589, was disclosed by Atlassian on October 5th and carries a CVSS rating of 9.3 out of 10, indicating its severe impact and ease of exploitation.

vulnerabilitycritical

Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities

Atlassian and Splunk have released patches addressing numerous critical and high-severity vulnerabilities across their product lines. The reported flaws could potentially be exploited by attackers to achieve arbitrary code execution, gain unauthorized access to sensitive data, and escalate privileges within affected systems. Users of Atlassian and Splunk products are strongly advised to apply…

vulnerability

Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant

A vulnerability, dubbed "RovoBlast" by Varonis Threat Labs, was discovered in Atlassian's enterprise AI assistant, Rovo, allowing for the exfiltration of company data through a single crafted link. The flaw was disclosed to Atlassian by Varonis, which published its analysis on August 7 after presenting the research at DEF CON 34. Atlassian has since confirmed and fixed the issue.

breachcritical

Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

A critical one-click vulnerability has been reported in Atlassian’s Rovo AI, which could have exposed enterprise data. The flaw, dubbed "RovoBlast" by researchers at Varonis, reportedly allowed for the exfiltration of sensitive information from linked Atlassian Confluence and Jira instances, as well as Microsoft SharePoint. The nature of a "one-click" vulnerability suggests a low barrier to…

atlassianhigh

Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Reports indicate that Atlassian's Rovo assistant has been found to contain vulnerabilities that could be exploited to exfiltrate sensitive data from Jira and Confluence instances. Two separate security firms have identified distinct mechanisms by which an attacker might trick Rovo into disclosing information. These findings highlight potential security risks associated with AI-powered…