Selected Atlassian Jira & Confluence vulnerability history.

A dated, source-linked selection of high-impact vulnerabilities in Atlassian’s self-hosted Confluence and Jira products, centered on flaws confirmed exploited in the wild. It is not a complete CVE catalog; Atlassian’s monthly bulletin index remains the current source for routine advisories. [11][3]

Vulnerability Published Last fact-checked 16 cited sources Research by SealTask

The short answer

Atlassian’s self-hosted Confluence and Jira Data Center and Server products carry a substantial recent record of critical vulnerabilities, several confirmed exploited in the wild. One of the most consequential is CVE-2023-22515, a broken access control flaw rated CVSS 10.0 by Atlassian, which threat actors exploited as a zero-day — before any patch existed — to create rogue administrator accounts on victim Confluence instances. CISA added it to the Known Exploited Vulnerabilities catalog on October 5, 2023, one day after Atlassian’s patch. [2][1][3]

Scope matters when reading this list: every vulnerability documented here affects customer-operated Data Center or Server deployments or customer-installed companion components (a macOS desktop app and the Assets Discovery network-scanning agent). Atlassian’s advisories state that Atlassian Cloud sites are not affected — the one nuance being CVE-2023-22523, whose affected Assets Discovery agent is also listed for use with Jira Service Management Cloud. This page is a product vulnerability record, not a record of a data breach at Atlassian: Have I Been Pwned holds no breach entry attributed to Atlassian itself, and the January 2024 Trello data scraping is documented separately. [11][1][8][9][15]

This is a selected vulnerability record for Atlassian’s self-hosted Confluence and Jira Data Center and Server products and customer-installed companion components. The vulnerable components run on customer-operated infrastructure; Atlassian Cloud sites are stated as unaffected, with one nuance — the Assets Discovery agent affected by CVE-2023-22523 is also listed for Jira Service Management Cloud. The separate Trello API-scraping event has its own record. [11][1][4][8][9][5]

Classification: A disclosed software weakness; a vulnerability alone is not evidence of a vendor data breach. Learn how incident terms differ.

Most severe flaws

Three CVSS 10.0 vulnerabilities disclosed within four months: CVE-2023-22515 (October 2023), CVE-2023-22518 (October–November 2023), CVE-2023-22527 (January 2024) [1][4][5]

Confirmed exploited (CISA KEV)

Four CVEs on this page appear in CISA’s Known Exploited Vulnerabilities catalog: CVE-2023-22515 (added October 5, 2023), CVE-2023-22518 (November 7, 2023), CVE-2023-22527 (January 24, 2024), and Jira’s CVE-2021-26086 (November 12, 2024) [3][14]

Zero-day exploitation

CVE-2023-22515 was exploited before a patch existed, with exploitation continuing post-patch, per the joint CISA/FBI/MS-ISAC advisory AA23-289A [2]

Affected deployments

Self-hosted Confluence and Jira Data Center/Server plus customer-installed companion components; Atlassian Cloud sites are stated as unaffected, except that CVE-2023-22523’s Assets Discovery agent is also listed for Jira Service Management Cloud [1][8][9][11]

Government response

Joint cybersecurity advisory AA23-289A issued October 16, 2023 by CISA, FBI, and MS-ISAC for CVE-2023-22515 [2]

Atlassian breach entries in HIBP

None — Have I Been Pwned holds no breach entry attributed to Atlassian (checked July 13, 2026) [15]

Incident timeline.

  1. Atlassian patches CVE-2023-22515 after zero-day exploitation

    Atlassian publishes its advisory for CVE-2023-22515, a broken access control vulnerability in Confluence Data Center and Server rated CVSS 10.0, affecting versions 8.0.0 through 8.5.1 and fixed in 8.3.3, 8.4.3, and 8.5.2. Versions before 8.0.0 and Atlassian Cloud sites are not affected. Per the joint advisory AA23-289A, threat actors had already exploited the flaw as a zero-day — before the fix existed — to create unauthorized Confluence administrator accounts. [1][2]

  2. CVE-2023-22515 added to CISA’s KEV catalog

    CISA adds CVE-2023-22515 to the Known Exploited Vulnerabilities catalog one day after the patch, confirming reliable evidence of active in-the-wild exploitation. [3]

  3. Joint CISA/FBI/MS-ISAC advisory AA23-289A

    CISA, the FBI, and MS-ISAC issue a joint cybersecurity advisory on active exploitation of CVE-2023-22515, noting exploitation continued after the patch and urging immediate upgrades. [2]

  4. CVE-2023-22518 disclosed

    Atlassian publishes an advisory for CVE-2023-22518, an improper authorization vulnerability in all versions of Confluence Data Center and Server, later raised to CVSS 10.0. Fixed in 7.19.16, 8.3.4, 8.4.4, 8.5.3, and 8.6.1; Atlassian Cloud is not affected. CISA issued an alert on the flaw on November 2, 2023. [4][10]

  5. Four critical advisories in one day

    Atlassian publishes advisories for four critical vulnerabilities: CVE-2023-22522 (remote code execution in Confluence Data Center and Server, CVSS 9.0), CVE-2023-22523 (RCE in Assets Discovery, CVSS 9.8), CVE-2023-22524 (RCE in the Atlassian Companion App for macOS, CVSS 9.6), and the bundled SnakeYAML library flaw CVE-2022-1471 affecting multiple products. [6][7][8][9]

  6. CVE-2023-22527 disclosed

    Atlassian publishes an advisory for CVE-2023-22527, an unauthenticated template-injection remote-code-execution vulnerability in out-of-date Confluence Data Center and Server versions, rated CVSS 10.0. Atlassian Cloud is not affected. [5]

  7. Jira’s CVE-2021-26086 added to CISA’s KEV catalog

    CISA adds CVE-2021-26086 — a path traversal vulnerability in Jira Server and Data Center that lets unauthenticated remote attackers read particular files via the /WEB-INF/web.xml endpoint (CVSS 5.3) — to the Known Exploited Vulnerabilities catalog, with a federal remediation due date of December 3, 2024. Known use in ransomware campaigns is recorded as “Unknown.” [14][13][3]

  8. Monthly bulletin illustrates the continuing patch stream

    Atlassian’s June 2026 bulletin lists 76 high-severity vulnerabilities and 24 critical-severity third-party dependency vulnerabilities fixed in current product releases. Atlassian explicitly says monthly-bulletin CVEs have been assessed as presenting non-critical risk in the way its products use the affected components, distinguishing them from out-of-band Critical Security Advisories. [12][11]

What this record is — and is not

This page documents publicly disclosed vulnerabilities (CVEs) in Atlassian’s self-hosted Confluence and Jira products, prioritizing flaws that were critical in severity or confirmed exploited in the wild. It is a product vulnerability record, not a record of a data breach at Atlassian: none of the entries below describe an intrusion into Atlassian’s own infrastructure, and Have I Been Pwned holds no breach entry attributed to Atlassian. [11][15]

Every vulnerability on this page affects customer-operated deployments — Confluence or Jira Data Center and Server installed on an organization’s own infrastructure — or customer-installed companion components: a macOS desktop app (CVE-2023-22524) and the Assets Discovery network-scanning agent (CVE-2023-22523). Atlassian’s advisories state that Atlassian Cloud sites are not affected, with the nuance that the affected Assets Discovery agent is also listed for use with Jira Service Management Cloud. Teams using Jira Cloud, Confluence Cloud, or Trello were not exposed to the server-side flaws on this page. [1][4][8][9][5]

CVE-2023-22515: the exploited Confluence zero-day (October 2023)

CVE-2023-22515 is a broken access control vulnerability in Confluence Data Center and Server versions 8.0.0 through 8.5.1, rated CVSS 10.0 by Atlassian. External attackers could exploit it on internet-accessible instances to create unauthorized Confluence administrator accounts, giving them full control of the instance. Versions before 8.0.0 and Atlassian Cloud are not affected. [1][2]

What makes this flaw stand out is the exploitation timeline. The joint CISA/FBI/MS-ISAC advisory AA23-289A states that threat actors exploited it as a zero-day — before Atlassian’s October 4, 2023 patch existed — and continued exploiting unpatched instances after the patch shipped. CISA added it to the Known Exploited Vulnerabilities catalog on October 5, 2023, and the joint advisory followed on October 16, 2023. [2][3]

CVE-2023-22518, CVE-2023-22527, and the December 2023 advisories

Four weeks after the zero-day, Atlassian disclosed CVE-2023-22518 (October 31, 2023) — an improper authorization vulnerability affecting all versions of Confluence Data Center and Server, whose severity Atlassian later raised to CVSS 10.0. Fixes shipped in 7.19.16, 8.3.4, 8.4.4, 8.5.3, and 8.6.1, and CISA issued an alert about the flaw on November 2, 2023. Atlassian Cloud was not affected. [4][10]

On December 5, 2023, Atlassian published four critical advisories in a single day: CVE-2023-22522, a remote-code-execution vulnerability in Confluence Data Center and Server (CVSS 9.0); CVE-2023-22523, RCE in the Assets Discovery scanning tool (CVSS 9.8), whose affected versions include Assets Discovery for Jira Service Management Cloud; CVE-2023-22524, RCE in the Atlassian Companion App for macOS (CVSS 9.6); and the bundled SnakeYAML library flaw CVE-2022-1471 affecting multiple products. [6][7][8][9]

On January 16, 2024, Atlassian disclosed CVE-2023-22527, an unauthenticated template-injection vulnerability in out-of-date Confluence Data Center and Server versions that allows remote code execution, rated CVSS 10.0. That made three separate CVSS 10.0 vulnerabilities in Atlassian’s self-hosted Confluence line disclosed within roughly four months. Atlassian Cloud was not affected by any of the three. [5][11]

CVE-2021-26086: the old Jira flaw that resurfaced in 2024

CVE-2021-26086 is a path traversal vulnerability in Jira Server and Jira Data Center that allows unauthenticated remote attackers to read particular files via the /WEB-INF/web.xml endpoint. Its CVSS 3.1 base score is a moderate 5.3 — but on November 12, 2024, more than three years after disclosure, CISA added it to the Known Exploited Vulnerabilities catalog, which requires reliable evidence of active in-the-wild exploitation, and set a federal remediation due date of December 3, 2024. [13][14][3]

The KEV entry records known use in ransomware campaigns as “Unknown.” The practical lesson for evaluators: moderate-severity flaws in widely deployed self-hosted software keep getting exploited years after patches exist, because unpatched instances remain reachable. This flaw affects self-hosted Jira only, not Jira Cloud. [3][13]

What this means when evaluating Jira or Confluence

Two distinct risk pictures emerge from the selected record. Self-hosting Atlassian products means owning an aggressive patch cadence: three CVSS 10.0 flaws in four months, one exploited before a patch existed, and a 2021 flaw added to CISA’s exploited catalog in 2024. Atlassian’s cloud services were not the vulnerable component in those server advisories; the exception in this page’s scope is the customer-installed Assets Discovery agent used with Jira Service Management Cloud. [11][2]

All software ships vulnerabilities, and a vendor publishing detailed advisories is doing the right thing — this record exists because Atlassian discloses. Use it to calibrate operational cost and exposure windows, not as proof that any alternative is flawless. [11]

What this selected history leaves to the live bulletin index

Atlassian moved to a monthly bulletin cadence for high-severity and dependency vulnerabilities. The June 2026 bulletin alone lists 76 high-severity and 24 critical-severity third-party dependency CVEs, while explaining that Atlassian assessed the product-specific risk of monthly-bulletin items as non-critical. Raw dependency CVSS scores therefore should not be presented as if they were all immediate critical product risks. [12][11]

This page intentionally focuses on the selected CISA Known Exploited Vulnerabilities entries and the concentrated 2023 critical-advisory wave. Readers operating Jira or Confluence Data Center should use Atlassian’s live advisory index and version-specific release notes, not this historical summary, to make patch decisions. [3][11]

How SealTask relates to this incident class

SealTask cannot claim immunity from vulnerabilities. For a compromise limited to content already stored on SealTask’s servers, protected workspace content is present as client-encrypted ciphertext rather than readable pages. That statement does not cover malicious code delivered to clients, compromised devices or sessions, account takeover, or server-visible account and operational metadata. It is a narrower storage-exposure distinction, not a claim that SealTask cannot suffer an incident. [16]

Frequently asked questions.

Has Atlassian been breached?

No product-attributed Atlassian entry was located in Have I Been Pwned on July 13, 2026, but HIBP absence does not answer whether every kind of incident has occurred. This page documents product vulnerabilities in self-hosted Jira and Confluence, several exploited in the wild on customers’ own instances. The January 2024 scraping of 15.1 million Trello profiles — an Atlassian-owned product — is documented separately. [15][3]

Was Jira Cloud or Confluence Cloud affected by CVE-2023-22515?

No. Atlassian’s advisory and the joint CISA/FBI/MS-ISAC advisory AA23-289A state that Atlassian Cloud sites are not affected. CVE-2023-22515 affected self-hosted Confluence Data Center and Server versions 8.0.0 through 8.5.1. [1][2]

What is CVE-2023-22515?

A broken access control vulnerability in Confluence Data Center and Server, rated CVSS 10.0 by Atlassian, that let external attackers create unauthorized administrator accounts. It was exploited as a zero-day before Atlassian’s October 4, 2023 patch, added to CISA’s Known Exploited Vulnerabilities catalog on October 5, 2023, and was the subject of joint advisory AA23-289A on October 16, 2023. [1][2][3]

Which Atlassian vulnerabilities were confirmed exploited in the wild?

Four of the vulnerabilities covered on this page appear in CISA’s Known Exploited Vulnerabilities catalog, which requires reliable evidence of active exploitation: CVE-2023-22515 (added October 5, 2023), CVE-2023-22518 (November 7, 2023), CVE-2023-22527 (January 24, 2024) — the latter two with known use in ransomware campaigns per the KEV record — and Jira’s CVE-2021-26086 (November 12, 2024). The KEV catalog is the authoritative list and is updated over time. [3][14]

Do these vulnerabilities affect Trello?

No. Trello is a cloud-hosted product, and the vulnerabilities on this page affect self-hosted Confluence or Jira Data Center/Server deployments and customer-installed components (a macOS companion app and the Assets Discovery scanning agent). Trello’s own documented incident — the January 2024 scraping of 15.1 million account profiles via an unauthenticated API — is covered on our Trello incident history page. [11][8]

Sources

All sources last accessed . Corrections: email hello@sealtask.com with a source and we will review and correct.

  1. 01
    Atlassian security advisory: CVE-2023-22515 - Vendor advisory — CVSS 10.0, affected versions 8.0.0–8.5.1, fixed in 8.3.3/8.4.3/8.5.2, Cloud not affected
  2. 02
    CISA/FBI/MS-ISAC joint advisory AA23-289A - October 16, 2023 joint advisory — zero-day and post-patch exploitation of CVE-2023-22515
  3. 03
    CISA Known Exploited Vulnerabilities catalog - KEV entries verified against CISA’s machine-readable feed: CVE-2023-22515 added October 5, 2023; CVE-2023-22518 added November 7, 2023; CVE-2023-22527 added January 24, 2024; CVE-2021-26086 added November 12, 2024
  4. 04
    Atlassian security advisory: CVE-2023-22518 - Vendor advisory published October 31, 2023 — improper authorization, severity later raised to CVSS 10.0, fixed in 7.19.16/8.3.4/8.4.4/8.5.3/8.6.1
  5. 05
    Atlassian security advisory: CVE-2023-22527 - Vendor advisory published January 16, 2024 — unauthenticated template-injection RCE, CVSS 10.0, Cloud not affected
  6. 06
    Atlassian: December 2023 security advisories overview - Vendor overview of the December 2023 advisories: CVE-2023-22522, CVE-2023-22523, CVE-2023-22524, and the bundled SnakeYAML CVE-2022-1471
  7. 07
    Atlassian security advisory: CVE-2023-22522 - Vendor advisory released December 5, 2023 — RCE in Confluence Data Center and Server, CVSS 9.0, Cloud not affected
  8. 08
    Atlassian security advisory: CVE-2023-22523 - Vendor advisory released December 5, 2023 — RCE in Assets Discovery, CVSS 9.8; lists Assets Discovery for Jira Service Management Cloud among affected products
  9. 09
    Atlassian security advisory: CVE-2023-22524 - Vendor advisory released December 5, 2023 — RCE in the Atlassian Companion App for macOS, CVSS 9.6; affects the Companion App only
  10. 10
  11. 11
    Atlassian security advisories & bulletins index - Canonical index of Atlassian’s security advisories across Jira, Confluence, and other products
  12. 12
    Atlassian: June 16, 2026 security bulletin - Current monthly bulletin example — 76 high-severity and 24 critical-severity third-party dependency CVEs, with Atlassian’s product-risk qualification
  13. 13
    NVD: CVE-2021-26086 - NIST record — Jira Server/Data Center path traversal via /WEB-INF/web.xml, CVSS 3.1 base 5.3
  14. 14
    CISA alert: five vulnerabilities added to the KEV catalog (November 12, 2024) - Announcement of the November 12, 2024 KEV additions, including CVE-2021-26086
  15. 15
    Have I Been Pwned: breached-sites index - No breach entry attributed to Atlassian; checked against the live index on July 13, 2026
  16. 16
    SealTask security architecture - What SealTask encrypts client-side and which operational metadata remains server-visible

Prefer task content protected at rest?

SealTask encrypts task titles, notes, comments, and attachments before upload. A compromise limited to stored server data would expose ciphertext for that content; account metadata, active sessions, client delivery, and devices remain separate risks.