# Atlassian Patches Dozens of Confluence, Jira Flaws

Published: 2026-07-27 · Severity: medium
Canonical: https://vorant.io/reports/e029fe3a-839e-55a3-85eb-b403c45e79b1/atlassian-patches-dozens-of-confluence-jira-flaws

> Atlassian released fixes for a large batch of vulnerabilities in Confluence and Jira Data Center products, some allowing remote code execution and privilege escalation.

ANSSI-CERT-FR issued an advisory covering a large batch of vulnerabilities affecting Atlassian's Data Center product line, including Confluence Data Center, Jira Software Data Center, and Jira Service Management Data Center. The disclosed flaws span a wide range of impact types including remote code execution, privilege escalation, denial of service, data integrity and confidentiality breaches, security policy bypass, and server-side request forgery (SSRF). The advisory references over 40 individual CVEs tied to more than 50 separate Atlassian security bulletins published on 21 July 2026.

No evidence of active exploitation is mentioned in the advisory, and no threat actor, malware, or campaign is associated with this disclosure. Organizations running affected versions of Confluence Data Center (prior to 10.2.14 or 9.2.22) or Jira Software/Service Management Data Center (prior to the respective patched versions) should apply vendor-supplied patches referenced in the accompanying Atlassian bulletins to mitigate risk, particularly given the presence of remote code execution vectors among the disclosed issues.

## Mentioned in this report

- Vulnerabilities: CVE-2022-37599, CVE-2022-37601, CVE-2022-37603, CVE-2025-11226, CVE-2025-14813, CVE-2025-62718, CVE-2025-69873, CVE-2026-12143, CVE-2026-21577, CVE-2026-21579, CVE-2026-2332, CVE-2026-29063, CVE-2026-29145, CVE-2026-29146, CVE-2026-33671, CVE-2026-34043, CVE-2026-40175, CVE-2026-42033, CVE-2026-42035, CVE-2026-42041, CVE-2026-42043, CVE-2026-42044, CVE-2026-42198, CVE-2026-42264, CVE-2026-42581, CVE-2026-42583, CVE-2026-44486, CVE-2026-44487, CVE-2026-44488, CVE-2026-44490, CVE-2026-44492, CVE-2026-44494, CVE-2026-44495, CVE-2026-44496, CVE-2026-44705, CVE-2026-46625, CVE-2026-47838, CVE-2026-4800, CVE-2026-48779, CVE-2026-6321

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0934

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/e029fe3a-839e-55a3-85eb-b403c45e79b1/atlassian-patches-dozens-of-confluence-jira-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
