How we count
Every figure on this page is a direct count of entries in CISA’s Known Exploited Vulnerabilities catalog attributed by CISA to Atlassian (KEV field vendorProject), refreshed daily. “Ransomware-linked” counts entries CISA marks as known to be used in ransomware campaigns; the remainder are “unknown” to CISA, not confirmed ransomware-free. A KEV listing means the vulnerability has been observed exploited in the wild. Snapshot as of 2026-08-31.
Exploited Atlassian vulnerabilities (CISA KEV)
| CVE | Product | Vulnerability | Added | |
|---|---|---|---|---|
| CVE-2021-26086 | Jira Server and Data Center | Atlassian Jira Server and Data Center Path Traversal Vulnerability | 2024-11-12 | |
| CVE-2023-22527 | Confluence Data Center and Server | Atlassian Confluence Data Center and Server Template Injection Vulnerability | 2024-01-24 | ransomware |
| CVE-2023-22518 | Confluence Data Center and Server | Atlassian Confluence Data Center and Server Improper Authorization Vulnerability | 2023-11-07 | ransomware |
| CVE-2023-22515 | Confluence Data Center and Server | Atlassian Confluence Data Center and Server Broken Access Control Vulnerability | 2023-10-05 | ransomware |
| CVE-2022-36804 | Bitbucket Server and Data Center | Atlassian Bitbucket Server and Data Center Command Injection Vulnerability | 2022-09-30 | |
| CVE-2022-26138 | Confluence | Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability | 2022-07-29 | |
| CVE-2022-26134 | Confluence Server/Data Center | Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability | 2022-06-02 | ransomware |
| CVE-2021-26085 | Confluence Server | Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability | 2022-03-28 | ransomware |
| CVE-2019-11581 | Jira Server and Data Center | Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability | 2022-03-07 | |
| CVE-2019-3398 | Confluence Server and Data Center | Atlassian Confluence Server and Data Center Path Traversal Vulnerability | 2021-11-03 | |
| CVE-2021-26084 | Confluence Server and Data Center | Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability | 2021-11-03 | ransomware |
| CVE-2019-11580 | Crowd and Crowd Data Center | Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability | 2021-11-03 | ransomware |
| CVE-2019-3396 | Confluence Server and Data Server | Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability | 2021-11-03 | ransomware |
← All vendors by exploited-vulnerability count
🤖 Generated by defend.network from the CISA KEV catalog. Counts are deterministic aggregates of official CISA data; verify individual advisories at the linked sources.