Skip to content
eastbaycyber

Atlassian: CISA KEV History

Every Atlassian vulnerability in the CISA Known Exploited Vulnerabilities catalog: confirmed in-the-wild exploitation, addition timeline, and ransomware linkage. Rebuilt automatically on every site deploy.

Snapshot: 2026-09-08 · Source: CISA KEV Catalog · Full KEV dashboard

KEV entries
13
Added, last 12 months
0
Ransomware-linked
8
Latest addition
2024-11-12

Atlassian KEV additions per month, last 24 months

2024-10: 0 added24/102024-11: 1 added12024-12: 0 added2025-01: 0 added25/012025-02: 0 added2025-03: 0 added2025-04: 0 added25/042025-05: 0 added2025-06: 0 added2025-07: 0 added25/072025-08: 0 added2025-09: 0 added2025-10: 0 added25/102025-11: 0 added2025-12: 0 added2026-01: 0 added26/012026-02: 0 added2026-03: 0 added2026-04: 0 added26/042026-05: 0 added2026-06: 0 added2026-07: 0 added26/072026-08: 0 added2026-09: 0 added

Most-listed products: Confluence Data Center and Server, Jira Server and Data Center, Confluence Server and Data Center, Bitbucket Server and Data Center, Confluence.

Latest 13 of 13 Atlassian KEV entries

CVEVulnerabilityAddedRansomware
CVE-2021-26086Atlassian Jira Server and Data Center Path Traversal Vulnerability2024-11-12No
CVE-2023-22527Atlassian Confluence Data Center and Server Template Injection Vulnerability2024-01-24Yes
CVE-2023-22518Atlassian Confluence Data Center and Server Improper Authorization Vulnerability2023-11-07Yes
CVE-2023-22515Atlassian Confluence Data Center and Server Broken Access Control Vulnerability2023-10-05Yes
CVE-2022-36804Atlassian Bitbucket Server and Data Center Command Injection Vulnerability2022-09-30No
CVE-2022-26138Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability2022-07-29No
CVE-2022-26134Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability2022-06-02Yes
CVE-2021-26085Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability2022-03-28Yes
CVE-2019-11581Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability2022-03-07No
CVE-2019-3398Atlassian Confluence Server and Data Center Path Traversal Vulnerability2021-11-03No
CVE-2021-26084Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Inject2021-11-03Yes
CVE-2019-11580Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability2021-11-03Yes
CVE-2019-3396Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability2021-11-03Yes

CVE links go to our explainer when one exists, otherwise to the NVD record.

Data: official CISA KEV catalog, fetched at build time. Figures may be reused with attribution to East Bay Cyber and CISA. See also the KEV Velocity Dashboard and all tracked vendors.