Vendor Exploitation Record

Atlassian (Confluence Data Center and Server) — Known Exploited Vulnerabilities

13 in CISA KEV · 8 ransomware-linked · as of 2026-08-31
In CISA KEV13 confirmed exploited
Ransomware-linked8 (62% of KEV, per CISA)
First KEV addition2021-11-03
Most recent2024-11-12

How we count

Every figure on this page is a direct count of entries in CISA’s Known Exploited Vulnerabilities catalog attributed by CISA to Atlassian (KEV field vendorProject), refreshed daily. “Ransomware-linked” counts entries CISA marks as known to be used in ransomware campaigns; the remainder are “unknown” to CISA, not confirmed ransomware-free. A KEV listing means the vulnerability has been observed exploited in the wild. Snapshot as of 2026-08-31.

Exploited Atlassian vulnerabilities (CISA KEV)

CVEProductVulnerabilityAdded
CVE-2021-26086Jira Server and Data CenterAtlassian Jira Server and Data Center Path Traversal Vulnerability2024-11-12
CVE-2023-22527Confluence Data Center and ServerAtlassian Confluence Data Center and Server Template Injection Vulnerability2024-01-24ransomware
CVE-2023-22518Confluence Data Center and ServerAtlassian Confluence Data Center and Server Improper Authorization Vulnerability2023-11-07ransomware
CVE-2023-22515Confluence Data Center and ServerAtlassian Confluence Data Center and Server Broken Access Control Vulnerability2023-10-05ransomware
CVE-2022-36804Bitbucket Server and Data CenterAtlassian Bitbucket Server and Data Center Command Injection Vulnerability2022-09-30
CVE-2022-26138ConfluenceAtlassian Questions For Confluence App Hard-coded Credentials Vulnerability2022-07-29
CVE-2022-26134Confluence Server/Data CenterAtlassian Confluence Server and Data Center Remote Code Execution Vulnerability2022-06-02ransomware
CVE-2021-26085Confluence ServerAtlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability2022-03-28ransomware
CVE-2019-11581Jira Server and Data CenterAtlassian Jira Server and Data Center Server-Side Template Injection Vulnerability2022-03-07
CVE-2019-3398Confluence Server and Data CenterAtlassian Confluence Server and Data Center Path Traversal Vulnerability2021-11-03
CVE-2021-26084Confluence Server and Data CenterAtlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability2021-11-03ransomware
CVE-2019-11580Crowd and Crowd Data CenterAtlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability2021-11-03ransomware
CVE-2019-3396Confluence Server and Data ServerAtlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability2021-11-03ransomware

← All vendors by exploited-vulnerability count

🤖 Generated by defend.network from the CISA KEV catalog. Counts are deterministic aggregates of official CISA data; verify individual advisories at the linked sources.

Track newly exploited vulnerabilities

Free daily briefing on CVEs added to CISA KEV and exploited in the wild.