Known Vulnerabilities for Confluence by Atlassian
Listed below are 10 of the newest known vulnerabilities associated with "Confluence" by "Atlassian".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-73498 json | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, conflue... | Not Provided | 2026-08-12 | 2026-08-13 |
| CVE-2026-73497 json | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). From 0.17.0 until 0.22.0... | Not Provided | 2026-09-14 | 2026-09-15 |
| CVE-2026-73496 json | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the con... | Not Provided | 2026-09-14 | 2026-09-14 |
| CVE-2026-21588 json | This High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0,... | Not Provided | 2026-09-15 | 2026-09-15 |
| CVE-2026-21587 json | This High severity Improper Authorization vulnerability was introduced in version 11.3.0 of Jira Service Management Data Cent... | Not Provided | 2026-09-15 | 2026-09-16 |
| CVE-2026-21586 json | This High severity Improper Authorization vulnerability was introduced in versions 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0,... | Not Provided | 2026-09-15 | 2026-09-16 |
| CVE-2026-21584 json | This High severity Improper Authorization vulnerability was introduced in versions 10.0.0, 10.1.0, 10.2.0, 11.0.0, 12.0.0, an... | Not Provided | 2026-08-18 | 2026-08-28 |
| CVE-2026-21582 json | This High severity BASM (Broken Authentication & Session Management) vulnerability known as CVE-2026-21582 was introduced in ... | Not Provided | 2026-08-18 | 2026-08-20 |
| CVE-2026-21580 json | This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced... | Not Provided | 2026-08-18 | 2026-08-21 |
| CVE-2026-21579 json | This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0... | Not Provided | 2026-07-21 | 2026-07-22 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Atlassian | Confluence | 7.6.1 | |||
| Application | Atlassian | Confluence | 7.6 | |||
| Application | Atlassian | Confluence | 7.5.2 | |||
| Application | Atlassian | Confluence | 7.5.1 | |||
| Application | Atlassian | Confluence | 7.5.0 | |||
| Application | Atlassian | Confluence | 7.4.2 | |||
| Application | Atlassian | Confluence | 7.4.1 | |||
| Application | Atlassian | Confluence | 7.4 | |||
| Application | Atlassian | Confluence | 7.3.5 | |||
| Application | Atlassian | Confluence | 7.3.4 | |||
| Application | Atlassian | Confluence | 7.3.3 | |||
| Application | Atlassian | Confluence | 7.3.2 | |||
| Application | Atlassian | Confluence | 7.3.1 | |||
| Application | Atlassian | Confluence | 7.3 | |||
| Application | Atlassian | Confluence | 7.2.2 | |||
| Application | Atlassian | Confluence | 7.2.1 | |||
| Application | Atlassian | Confluence | 7.2.0 | |||
| Application | Atlassian | Confluence | 7.1.2 | |||
| Application | Atlassian | Confluence | 7.1.1 | |||
| Application | Atlassian | Confluence | 7.1.0 |