Atlassian: CISA KEV History
Every Atlassian vulnerability in the CISA Known Exploited Vulnerabilities catalog: confirmed in-the-wild exploitation, addition timeline, and ransomware linkage. Rebuilt automatically on every site deploy.
Snapshot: 2026-09-08 · Source: CISA KEV Catalog · Full KEV dashboard
KEV entries
13
Added, last 12 months
0
Ransomware-linked
8
Latest addition
2024-11-12
Atlassian KEV additions per month, last 24 months
Most-listed products: Confluence Data Center and Server, Jira Server and Data Center, Confluence Server and Data Center, Bitbucket Server and Data Center, Confluence.
Latest 13 of 13 Atlassian KEV entries
| CVE | Vulnerability | Added | Ransomware |
|---|---|---|---|
| CVE-2021-26086 | Atlassian Jira Server and Data Center Path Traversal Vulnerability | 2024-11-12 | No |
| CVE-2023-22527 | Atlassian Confluence Data Center and Server Template Injection Vulnerability | 2024-01-24 | Yes |
| CVE-2023-22518 | Atlassian Confluence Data Center and Server Improper Authorization Vulnerability | 2023-11-07 | Yes |
| CVE-2023-22515 | Atlassian Confluence Data Center and Server Broken Access Control Vulnerability | 2023-10-05 | Yes |
| CVE-2022-36804 | Atlassian Bitbucket Server and Data Center Command Injection Vulnerability | 2022-09-30 | No |
| CVE-2022-26138 | Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability | 2022-07-29 | No |
| CVE-2022-26134 | Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability | 2022-06-02 | Yes |
| CVE-2021-26085 | Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability | 2022-03-28 | Yes |
| CVE-2019-11581 | Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability | 2022-03-07 | No |
| CVE-2019-3398 | Atlassian Confluence Server and Data Center Path Traversal Vulnerability | 2021-11-03 | No |
| CVE-2021-26084 | Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Inject | 2021-11-03 | Yes |
| CVE-2019-11580 | Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability | 2021-11-03 | Yes |
| CVE-2019-3396 | Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability | 2021-11-03 | Yes |
CVE links go to our explainer when one exists, otherwise to the NVD record.
Data: official CISA KEV catalog, fetched at build time. Figures may be reused with attribution to East Bay Cyber and CISA. See also the KEV Velocity Dashboard and all tracked vendors.