Exploitation timeline
Threadlinqs has recorded 5 Atlassian CVEs published between and . The busiest month was 2026-10 (1 new CVE). 4 of them (80%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 5 of 5 tracked Atlassian CVEs.
- CVE-2022-26134critical 9.8KEVRansomwareEPSS 100%
- CVE-2021-26086medium 5.3KEVEPSS 100%
- CVE-2023-22515critical 10KEVRansomwareEPSS 99.2%
- CVE-2019-11580critical 9.8KEVRansomwareEPSS 95.4%
- CVE-2026-21589critical 9.3EPSS 0.7%
Products affected
Threadlinqs normalises CPE and CNA product records across all 5 CVEs; 12 distinct Atlassian products are affected. The most frequently affected:
- Confluence Data Center 3 CVEs
- Confluence Server 2 CVEs
- Bamboo Data Center 1 CVE
- Bitbucket Data Center 1 CVE
- Crowd 1 CVE
- Crowd Data Center 1 CVE
- Crucible Data Center 1 CVE
- Fisheye Data Center 1 CVE
- Jira Data Center 1 CVE
- Jira Server 1 CVE
- Jira Service Management Data Center 1 CVE
- Jira Software Data Center 1 CVE
Threat activity
13 tracked threat campaigns reference Atlassian products or exploit Atlassian CVEs:
- Evooo1Bot: Multi-Functional Mirai-Based Linux Botnet Exploiting 18 Known CVEs in Internet-Facing DevicesHIGH
- Atlassian Data Center critical unauthenticated arbitrary file access vulnerability (CVE-2026-21589) across Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible and FisheyeCRITICAL
- RovoBlast: One-Click rovoChatPrompt Parameter-to-Prompt Injection in Atlassian Rovo Exposes Confluence, Jira, SharePoint, and Bitbucket DataCRITICAL
- RovoBlast: One-Click Parameter-to-Prompt Injection in Atlassian Rovo AI Exposes Confluence, Jira, and SharePoint DataCRITICAL
- CVE-2026-34486: Apache Tomcat EncryptInterceptor Bypass Actively Exploited in SnowLight and AI-Assisted CampaignsHIGH
- Alleged Żabka Polska Breach: 541K Jira Issues, 230K IT Tickets, 89 GitLab Repos, and Cloudflare/MongoDB/Broker Credentials Offered for €5,000HIGH
- Klue Supply Chain Breach: OAuth Token Harvesting & Salesforce CRM Data ExfiltrationCRITICAL
- Claude Code MCP Traffic Hijack via Malicious npm postinstall — ~/.claude.json Tampering Proxies MCP Endpoints to Steal Persistent OAuth Bearer Tokens (Mitiga Labs PoC)HIGH
- Multi-Stage Linux Intrusion via End-of-Life F5 BIG-IP and Unpatched Confluence — SSH Foothold to NTLM Relay (CVE-2025-33073, CVE-2025-53521)HIGH
- F5 BIG-IP Edge Appliance Abused for SSH Pivot → Confluence RCE → CVE-2025-33073 Kerberos Relay to Active Directory (Microsoft Defender Research)HIGH
- APT35 (Charming Kitten) GCC Pre-Positioning Cyber Reconnaissance Campaign Enabling Kinetic TargetingCRITICAL
- Malicious Next.js Repositories — Developer-Targeting C2 Campaign via VSCode Workspace Abuse, Job-Themed Lures, and Staged JavaScript ExecutionCRITICAL
- TGR-STA-1030 / UNC6619 Shadow Campaigns — China-Nexus APT Breaches 70+ Government Organizations Across 37 Countries, Recons 155 Nations, Novel ShadowGuard eBPF Rootkit, Diaoyu Loader, Event-Driven Geopolitical TargetingCRITICAL
Threat actors targeting Atlassian
Named threat actors attributed to campaigns that involve Atlassian products or CVEs, with the number of linked campaigns:
How to prioritise Atlassian patching
This order follows the data Threadlinqs holds for Atlassian, not a generic severity checklist:
- 4 of 5 Atlassian CVEs (80%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2022-26134, CVE-2021-26086, CVE-2023-22515.
- 3 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are CVE-2026-21589 (0.7%).
- 4 CVEs score Critical and 0 High on CVSS v3 (maximum 10, average 8.8); sequence these after KEV and high-EPSS items.
- 5 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-10 and refresh daily.