Atlassian has disclosed and patched a batch of security vulnerabilities across its product suite, with the most critical being a man-in-the-middle flaw in Confluence Data Center rated at a maximum CVSS score of 10 out of 10.
The vulnerability, tracked as CVE-2026-45674, allows an attacker to intercept and eavesdrop on connections to Confluence Data Center installations. Atlassian describes it as affecting both Data Center and Server deployments of Confluence.
In addition to the critical Confluence flaw, Atlassian patched multiple high-severity issues in Bamboo:
- CVE-2026-54512 (high): Allows attackers to crash Bamboo installations remotely - CVE-2026-54513 (high): Enables remote code execution on affected systems
The following products and versions have been patched:
- Bamboo Data Center and Server: 12.1.11 LTS, 10.2.23 LTS - Bitbucket Data Center and Server: 10.4.3, 10.2.7 LTS, 9.4.24 LTS - Confluence Data Center and Server: 10.2.18 LTS, 9.2.25 LTS - Crowd Data Center and Server: 7.2.3 - Fisheye/Crucible: 4.9.14 - Jira Data Center and Server: 11.3.11 LTS, 10.3.25 LTS - Jira Service Management Data Center and Server: 11.3.11 LTS, 10.3.25 LTS
Atlassian says there are no known active exploits in the wild, but given the severity of the Confluence flaw and the public nature of the patches, administrators should prioritize installing the updates immediately.
The announcement comes as part of Atlassian's regular security maintenance cycle, but the presence of a CVSS 10 vulnerability makes this round particularly urgent for organizations running self-hosted Confluence deployments.




