Atlassian Confluence Data Center

9 known vulnerabilities in Atlassian Confluence Data Center, 6 critical, 6 actively exploited, with patch priority, exploit likelihood and the news covering…

Recently exploited

  • CVE-2023-22527 CVSS 9.8 critical · actively exploited Atlassian Confluence Data Center and Server Template Injection Vulnerability
  • CVE-2023-22518 CVSS 9.8 critical · actively exploited Atlassian Confluence Data Center and Server Improper Authorization Vulnerability
  • CVE-2023-22515 CVSS 9.8 critical · actively exploited Atlassian Confluence Data Center and Server Broken Access Control Vulnerability
  • CVE-2022-26134 CVSS 9.8 critical · actively exploited Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability
  • CVE-2021-26084 CVSS 9.8 critical · actively exploited Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability
  • CVE-2021-26085 CVSS 5.3 medium · actively exploited Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability

Latest vulnerabilities

  • CVE-2026-21589 CVSS 9.3 critical h3. Summary This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software…
  • CVE-2026-21588 CVSS 7.1 high This High severity DoS (Denial of Service) vulnerability was introduced in versions 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1…
  • CVE-2026-21586 CVSS 7.1 high This High severity Improper Authorization vulnerability was introduced in versions 7.4.0, 7.13.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0…
  • CVE-2023-22527 CVSS 9.8 critical · actively exploited Atlassian Confluence Data Center and Server Template Injection Vulnerability
  • CVE-2023-22518 CVSS 9.8 critical · actively exploited Atlassian Confluence Data Center and Server Improper Authorization Vulnerability
  • CVE-2023-22515 CVSS 9.8 critical · actively exploited Atlassian Confluence Data Center and Server Broken Access Control Vulnerability
  • CVE-2022-26134 CVSS 9.8 critical · actively exploited Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability
  • CVE-2021-26084 CVSS 9.8 critical · actively exploited Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability
  • CVE-2021-26085 CVSS 5.3 medium · actively exploited Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability