Vulnerabilities

Atlassian Patches Critical Vulnerabilities in Confluence, Crowd

Atlassian has released patches for 12 critical- and high-severity vulnerabilities in Bamboo, Bitbucket, Confluence, Crowd, and Jira.

Atlassian security updates

Atlassian this week announced the rollout of patches for 12 critical- and high-severity vulnerabilities in its Bamboo, Bitbucket, Confluence, Crowd, and Jira products.

The company released fixes for five critical-severity issues in Confluence Data Center and Server and Crowd Data Center and Server that were discovered in third-party dependencies used within the two products.

Updates released for Confluence Data Center and Server address two critical flaws in Apache Tomcat. Tracked as CVE-2024-50379 and CVE-2024-56337 (CVSS score of 9.8), the two issues could be exploited by unauthenticated attackers to achieve remote code execution (RCE), the company warns.

The two flaws were addressed in Crowd Data Center and Server as well, along with a third critical bug in Apache Tomcat, tracked as CVE-2024-52316 (CVSS score of 9.8). Also exploitable by unauthenticated attackers, the defect could lead to authentication bypass, Atlassian says.

The updates for Crowd also resolve a high-severity denial of service (DoS) vulnerability in ua-parser-js, which is tracked as CVE-2022-25927, Atlassian notes in its February 2025 security bulletin.

The company rolled out fixes for two high-severity DoS flaws in Bamboo Data Center and Server, affecting Protocol Buffers (CVE-2024-7254) and the XStream library (CVE-2024-47072), and for a high-severity RCE bug in Bitbucket Data Center and Server, impacting the Java SDK of Apache Avro (CVE-2024-47561).

Advertisement. Scroll to continue reading.

The DoS security defect in Protocol Buffers was also addressed in Jira Data Center and Server, Atlassian announced.

The company makes no mention of any of these vulnerabilities being exploited against its products, but urges customers to update their installations as soon as possible.

“To fix all the vulnerabilities impacting your product(s), Atlassian recommends patching your instances to the latest version or one of the fixed versions for each product,” the company notes.

Related: Atlassian, Splunk Patch High-Severity Vulnerabilities

Related: Atlassian Patches Vulnerabilities in Bitbucket, Confluence, Jira

Related: Atlassian Patches Vulnerabilities in Bamboo, Bitbucket, Confluence, Crowd

Related: Details of Atlassian Confluence RCE Vulnerability Disclosed

Related Content

Vulnerabilities

More than 200 vulnerabilities have been patched to date this year, compared to only 16 in 2025 and 22 in 2024. 

Vulnerabilities

The type confusion bug can lead to V8 sandbox escape and control-flow hijacking of the host process.

Cloud Security

A total of 22 patches were releaased, a majority for code execution, privilege escalation, and information disclosure vulnerabilities.

Vulnerabilities

The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware.

Vulnerabilities

Exploitation of the Zimbra Collaboration vulnerability CVE-2026-73570 has been observed by Poland’s CERT Polska.

Vulnerabilities

The flaws could be exploited to execute arbitrary code, access sensitive information, and elevate privileges.

Vulnerabilities

The critical-severity flaw allows attackers to send HTTP requests to internal endpoints and extract sensitive information.

Vulnerabilities

The flaws could lead to remote code execution, authentication bypasses, and path traversal attacks.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version