Security Bulletin - June 16 2026

セキュリティ アドバイザリーおよびセキュリティ情報

このページの内容

お困りですか?

アトラシアン コミュニティをご利用ください。

コミュニティに質問

June 2026 Security Bulletin

The vulnerabilities reported in this Security Bulletin include 76 high-severity vulnerabilities and 24 critical-severity third-party vulnerabilities, which have been fixed in new versions of our products released in the last month.

CVEs reported in monthly Security Bulletins have been assessed as presenting a non-critical risk to Atlassian customers. Atlassian issues Critical Security Advisories for vulnerabilities that pose an immediate critical risk based on how our products actually use the affected components outside of our monthly Security Bulletin schedule as necessary.

Vulnerabilities are discovered through our Bug Bounty program, pen-testing processes, and third-party library scans.

The increase in reported vulnerabilities this month is attributed to externally coordinated security research and patching activity across several widely-used open-source libraries. These upstream events are reflected in our dependency scanning results and do not indicate a change in Atlassian's own security posture.

INSTRUCTIONS

To fix all the vulnerabilities impacting your product(s), Atlassian recommends patching your instances to the latest version or one of the Fixed Versions for each product below. The listed Fixed Versions for each product are current as of June 16, 2026 (date of publication); visit the linked product Release Notes for the most up-to-date versions.

To search for CVEs or check your product versions for disclosed vulnerabilities, check the Vulnerability Disclosure Portal.

リリースされたセキュリティ脆弱性
Product & Release Notes影響を受けるバージョン修正対象バージョンVulnerability SummaryCVE IDCVSS Severity
Bamboo Data Center and Server
  • 12.1.0 to 12.1.7 (LTS)
  • 12.0.0 から 12.0.2
  • 11.0.0 から 11.0.8
  • 10.2.0 to 10.2.19 (LTS)
  • 10.1.0 から 10.1.1
  • 10.0.0 から 10.0.3
  • 12.1.8 (LTS) recommended Data Center Only
  • 10.2.20 (LTS) Data Center Only
RCE (Remote Code Execution) org.apache.activemq:activemq-broker Dependency in Bamboo Data CenterCVE-2026-410448.8 High
SSRF (Server-Side Request Forgery) axios Dependency in Bamboo Data CenterCVE-2026-444928.6 High
Information Disclosure axios Dependency in Bamboo Data CenterCVE-2026-444878.2 High
DoS (Denial of Service) axios Dependency in Bamboo Data CenterCVE-2026-444887.5 High
HTTP Request Smuggling io.netty:netty-codec-http Dependency in Bamboo Data CenterCVE-2026-425857.5 High
DoS (Denial of Service) io.netty:netty-codec Dependency in Bamboo Data CenterCVE-2026-425837.5 High
Information Disclosure axios Dependency in Bamboo Data CenterCVE-2026-444867.5 High
SSRF (Server-Side Request Forgery) axios Dependency in Bamboo Data CenterCVE-2026-420387.5 High
DoS (Denial of Service) org.apache.tomcat:tomcat-catalina Dependency in Bamboo Data CenterCVE-2026-412847.5 High
DoS (Denial of Service) axios Dependency in Bamboo Data CenterCVE-2026-444967.5 High
DoS (Denial of Service) io.netty:netty-codec Dependency in Bamboo Data CenterCVE-2026-425877.5 High
Business Logic Vulnerability org.apache.tomcat:tomcat-catalina Dependency in Bamboo Data CenterCVE-2026-435137.5 High
DoS (Denial of Service) org.postgresql:postgresql Dependency in Bamboo Data CenterCVE-2026-410447.5 High
Injection axios Dependency in Bamboo Data CenterCVE-2026-420337.4 High
Injection axios Dependency in Bamboo Data CenterCVE-2026-420357.4 High
Bitbucket Data Center および Server
  • 10.3.0
  • 10.2.0 to 10.2.3 (LTS)
  • 10.1.1 から 10.1.5
  • 10.0.0 から 10.0.2
  • 9.6.0 から 9.6.5
  • 9.5.0 から 9.5.2
  • 9.4.0 to 9.4.20 (LTS)
  • 9.3.0 から 9.3.2
  • 9.2.0 から 9.2.1
  • 9.1.0 から 9.1.1
  • 9.0.1
  • 10.3.1 Data Center Only
  • 10.2.4 (LTS) recommended Data Center Only
  • 9.4.21 (LTS) Data Center Only
SSRF (Server-Side Request Forgery) axios Dependency in Bitbucket Data CenterCVE-2026-420387.5 High
DoS (Denial of Service) @isaacs/brace-expansion Dependency in Bitbucket Data CenterCVE-2026-451497.5 High
DoS (Denial of Service) org.apache.tomcat.embed:tomcat-embed-core Dependency in Bitbucket Data CenterCVE-2026-412847.5 High
MITM (Man-in-the-Middle) org.apache.tomcat.embed:tomcat-embed-core Dependency in Bitbucket Data CenterCVE-2026-247347.5 High
Injection axios Dependency in Bitbucket Data CenterCVE-2026-420337.4 High
Injection axios Dependency in Bitbucket Data CenterCVE-2026-420357.4 High
Confluence Data Center および Server
  • 10.2.0 to 10.2.11 (LTS)
  • 10.1.0 から 10.1.2
  • 10.0.2 から 10.0.3
  • 9.5.1 から 9.5.4
  • 9.4.0 から 9.4.1
  • 9.3.1 から 9.3.2
  • 9.2.0 to 9.2.20 (LTS)
  • 9.1.0 から 9.1.1
  • 9.0.1 から 9.0.3
  • 8.9.4 から 8.9.8
  • 8.5.12 to 8.5.31 (LTS)
  • 7.19.25 to 7.19.30 (LTS)
  • 10.2.13 (LTS) recommended Data Center Only
  • 9.2.21 (LTS) Data Center Only
Injection org.apache.tomcat:tomcat-coyote Dependency in Confluence Data CenterCVE-2026-41293

9.8 Critical

This is a vulnerability in a non-Atlassian Confluence dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

BASM (Broken Authentication & Session Management) org.apache.tomcat:tomcat-catalina Dependency in Confluence Data Center and ServerCVE-2026-43512

9.8 Critical

This is a vulnerability in a non-Atlassian Confluence dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

Injection io.netty:netty-codec-dns Dependency in Confluence Data CenterCVE-2026-42579

9.1 Critical

This is a vulnerability in a non-Atlassian Confluence dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

HTTP Request Smuggling io.netty:netty-codec-http Dependency in Confluence Data CenterCVE-2026-42584

9.1 Critical

This is a vulnerability in a non-Atlassian Confluence dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

Improper Authorization org.apache.tomcat:tomcat-catalina Dependency in Confluence Data CenterCVE-2026-43515

9.1 Critical

This is a vulnerability in a non-Atlassian Confluence dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

DoS (Denial of Service) minimatch Dependency in Confluence Data CenterCVE-2026-269968.7 High
DoS (Denial of Service) org.apache.tomcat:tomcat-catalina Dependency in Confluence Data CenterCVE-2026-412847.5 High
Business Logic Vulnerability Apache Tomcat Dependency in Confluence Data CenterCVE-2026-435137.5 High
HTTP Request Smuggling ws Dependency in Confluence Data CenterCVE-2026-457367.5 High
HTTP Request Smuggling io.netty:netty-codec-http Dependency in Confluence Data CenterCVE-2026-425857.5 High
DoS (Denial of Service) minimatch Dependency in Confluence Data CenterCVE-2026-279047.5 High
DoS (Denial of Service) minimatch Dependency in Confluence Data CenterCVE-2026-279037.5 High
DoS (Denial of Service) @isaacs/brace-expansion Dependency in Confluence Data CenterCVE-2026-451497.5 High
DoS (Denial of Service) io.netty:netty-codec-http Dependency in Confluence Data Center and ServerCVE-2026-425877.5 High
Information Disclosure org.apache.tomcat:tomcat-websocket Dependency in Confluence Data CenterCVE-2026-424987.3 High
Crowd Data Center and Server
  • 7.2.0
  • 7.1.0 から 7.1.5
  • 7.0.0 から 7.0.2
  • 6.3.0 から 6.3.6
  • 6.2.0 から 6.2.6
  • 6.1.0 から 6.1.7
  • 6.0.0 から 6.0.10
  • 5.3.2 から 5.3.8
  • 7.2.1 recommended Data Center Only
HTTP Request Smuggling io.netty:netty-codec-http Dependency in Crowd Data CenterCVE-2026-42581

9.8 Critical

This is a vulnerability in a non-Atlassian Crowd dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

Business Logic Vulnerability org.springframework.security:spring-security-web Dependency in Crowd Data CenterCVE-2026-22732

9.1 Critical

This is a vulnerability in a non-Atlassian Crowd dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

HTTP Request Smuggling io.netty:netty-codec-http Dependency in Crowd Data CenterCVE-2026-42584

9.1 Critical

This is a vulnerability in a non-Atlassian Crowd dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

DoS (Denial of Service) org.postgresql:postgresql Dependency in Crowd Data CenterCVE-2026-421987.5 High
DoS (Denial of Service) io.netty:netty-codec Dependency in Crowd Data CenterCVE-2026-425837.5 High
HTTP Request Smuggling io.netty:netty-codec-http Dependency in Crowd Data CenterCVE-2026-425857.5 High
DoS (Denial of Service) io.netty:netty-codec-http2 Dependency in Crowd Data CenterCVE-2026-425877.5 High
Fisheye/Crucible
  • 4.9.0 から 4.9.10
  • 4.9.11 recommended
Improper Authorization org.springframework.security:spring-security-core Dependency in Crucible Data Center and ServerCVE-2024-222578.2 High
BASM (Broken Authentication & Session Management) org.springframework.security:spring-security-core Dependency in Crucible Data Center and ServerCVE-2025-222287.4 High
BASM (Broken Authentication & Session Management) org.springframework.security:spring-security-core Dependency in Crucible Data Center and ServerCVE-2019-112727.3 High
Jira Data Center および Server
  • 11.3.0 to 11.3.6 (LTS)
  • 11.2.0 から 11.2.1
  • 11.1.0 から 11.1.1
  • 11.0.0 から 11.0.1
  • 10.7.1 から 10.7.4
  • 10.6.0 から 10.6.1
  • 10.5.0 から 10.5.1
  • 10.4.0 から 10.4.1
  • 10.3.0 to 10.3.21 (LTS)
  • 10.2.0 から 10.2.1
  • 10.1.1 から 10.1.2
  • 10.0.0 から 10.0.1
  • 9.17.0 から 9.17.5
  • 9.12.11 to 9.12.35 (LTS)
  • 11.3.7 (LTS) recommended Data Center Only
  • 10.3.22 (LTS) Data Center Only
SSRF (Server-Side Request Forgery) axios Dependency in Jira Software Data CenterCVE-2026-42043

10 Critical

This is a vulnerability in a non-Atlassian Jira Software dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

Prototype Pollution axios Dependency in Jira Software Data Center and ServerCVE-2026-40175

10 Critical

This is a vulnerability in a non-Atlassian Jira Software dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

Injection org.apache.tomcat:tomcat-catalina Dependency in Jira Software Data CenterCVE-2026-41293

9.8 Critical

This is a vulnerability in a non-Atlassian Jira Software dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

BASM (Broken Authentication & Session Management) org.apache.tomcat:tomcat-catalina Dependency in Jira Software Data Center and ServerCVE-2026-43512

9.8 Critical

This is a vulnerability in a non-Atlassian Jira Software dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

Injection org.apache.tomcat:tomcat-coyote Dependency in Jira Software Data CenterCVE-2026-41293

9.8 Critical

This is a vulnerability in a non-Atlassian Jira Software dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

Improper Authorization org.apache.tomcat:tomcat-coyote Dependency in Jira Software Data CenterCVE-2026-43515

9.1 Critical

This is a vulnerability in a non-Atlassian Jira Software dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

Improper Authorization org.apache.tomcat:tomcat-catalina Dependency in Jira Software Data CenterCVE-2026-43515

9.1 Critical

This is a vulnerability in a non-Atlassian Jira Software dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

HTTP Request Smuggling io.netty:netty-codec-http Dependency in Jira Software Data CenterCVE-2026-42584

9.1 Critical

This is a vulnerability in a non-Atlassian Jira Software dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

Injection axios Dependency in Jira Software Data CenterCVE-2026-42264

9.1 Critical

This is a vulnerability in a non-Atlassian Jira Software dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

DoS (Denial of Service) io.netty:netty-codec-http2 Dependency in Jira Software Data CenterCVE-2026-338718.7 High
RCE (Remote Code Execution) react-router Dependency in Jira Software Data CenterCVE-2026-422118.1 High
XSS (Cross Site Scripting) turbo-stream Dependency in Jira Software Data CenterCVE-2026-340777.5 High
Information Disclosure org.apache.tomcat:tomcat-catalina Dependency in Jira Software Data CenterCVE-2026-344877.5 High
HTTP Request Smuggling io.netty:netty-codec-http Dependency in Jira Data CenterCVE-2026-425857.5 High
DoS (Denial of Service) org.apache.tomcat:tomcat-catalina Dependency in Jira Software Data CenterCVE-2026-412847.5 High
DoS (Denial of Service) nth-check Dependency in Jira Software Data CenterCVE-2021-38037.5 High
Business Logic Vulnerability Apache Tomcat Dependency in Jira Software Data CenterCVE-2026-435137.5 High
DoS (Denial of Service) minimatch Dependency in Jira Software Data CenterCVE-2026-279037.5 High
DoS (Denial of Service) react-router Dependency in Jira Software Data CenterCVE-2026-423427.5 High
HTTP Request Smuggling io.netty:netty-codec-http Dependency in Jira Software Data CenterCVE-2026-338707.5 High
SSRF (Server-Side Request Forgery) axios Dependency in Jira Software Data CenterCVE-2026-420387.5 High
DoS (Denial of Service) minimatch Dependency in Jira Software Data CenterCVE-2026-279047.5 High
Cryptographic Failure org.apache.tomcat:tomcat-catalina Dependency in Jira Software Data CenterCVE-2026-344867.5 High
Injection axios Dependency in Jira Software Data CenterCVE-2026-420357.4 High
Injection axios Dependency in Jira Software Data CenterCVE-2026-420337.4 High
RCE (Remote Code Execution) axios Dependency in Jira Software Data CenterCVE-2026-444957 High
Jira Service Management Data Center および Server
  • 11.3.0 to 11.3.6 (LTS)
  • 11.2.0 から 11.2.1
  • 11.1.0 から 11.1.1
  • 11.0.0 から 11.0.1
  • 10.7.1 から 10.7.4
  • 10.6.0 から 10.6.1
  • 10.5.0 から 10.5.1
  • 10.4.0 から 10.4.1
  • 10.3.0 to 10.3.21 (LTS)
  • 10.2.0 から 10.2.1
  • 10.1.1 から 10.1.2
  • 10.0.0 から 10.0.1
  • 5.17.0 から 5.17.5
  • 11.3.7 (LTS) recommended Data Center Only
  • 10.3.22 (LTS) Data Center Only
Prototype Pollution axios Dependency in Jira Service Management Data Center and ServerCVE-2026-40175

10 Critical

This is a vulnerability in a non-Atlassian Jira Service Management dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

SSRF (Server-Side Request Forgery) axios Dependency in Jira Service Management Data CenterCVE-2026-42043

10 Critical

This is a vulnerability in a non-Atlassian Jira Service Management dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

Injection org.apache.tomcat:tomcat-coyote Dependency in Jira Service Management Data CenterCVE-2026-41293

9.8 Critical

This is a vulnerability in a non-Atlassian Jira Service Management dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

Authentication Bypass org.apache.tomcat:tomcat-catalina Dependency in Jira Service Management Data CenterCVE-2026-43512

9.8 Critical

This is a vulnerability in a non-Atlassian Jira Service Management dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

HTTP Request Smuggling io.netty:netty-codec-http Dependency in Jira Service Management Data CenterCVE-2026-42584

9.1 Critical

This is a vulnerability in a non-Atlassian Jira Service Management dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

Improper Authorization org.apache.tomcat:tomcat-catalina Dependency in Jira Service Management Data CenterCVE-2026-43515

9.1 Critical

This is a vulnerability in a non-Atlassian Jira Service Management dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

Injection axios Dependency in Jira Service Management Data CenterCVE-2026-42264

9.1 Critical

This is a vulnerability in a non-Atlassian Jira Service Management dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

DoS (Denial of Service) io.netty:netty-codec-http2 Dependency in Jira Service Management Data CenterCVE-2026-338718.7 High
RCE (Remote Code Execution) react-router Dependency in Jira Service Management Data CenterCVE-2026-422118.1 High
DoS (Denial of Service) io.netty:netty-codec Dependency in Jira Service Management Data CenterCVE-2026-425877.5 High
XSS (Cross Site Scripting) turbo-stream Dependency in Jira Service Management Data CenterCVE-2026-340777.5 High
DoS (Denial of Service) minimatch Dependency in Jira Service Management Data CenterCVE-2026-279037.5 High
HTTP Request Smuggling io.netty:netty-codec-http Dependency in Jira Service Management Data CenterCVE-2026-425857.5 High
Security Misconfiguration org.apache.tomcat:tomcat-catalina Dependency in Jira Service Management Data CenterCVE-2026-344867.5 High
DoS (Denial of Service) org.apache.tomcat:tomcat-catalina Dependency in Jira Service Management Data CenterCVE-2026-412847.5 High
DoS (Denial of Service) minimatch Dependency in Jira Service Management Data CenterCVE-2026-279047.5 High
DoS (Denial of Service) io.netty:netty-codec Dependency in Jira Service Management Data CenterCVE-2026-425837.5 High
SSRF (Server-Side Request Forgery) axios Dependency in Jira Service Management Data CenterCVE-2026-420387.5 High
Business Logic Vulnerability Apache Tomcat Dependency in Jira Service Management Data CenterCVE-2026-435137.5 High
DoS (Denial of Service) nth-check Dependency in Jira Service Management Data CenterCVE-2021-38037.5 High
DoS (Denial of Service) react-router Dependency in Jira Service Management Data CenterCVE-2026-423427.5 High
Cryptographic Failure org.apache.tomcat:tomcat-catalina Dependency in Jira Service Management Data CenterCVE-2026-291297.5 High
HTTP Request Smuggling io.netty:netty-codec-http Dependency in Jira Service Management Data CenterCVE-2026-338707.5 High
Information Disclosure org.apache.tomcat:tomcat-catalina Dependency in Jira Service Management Data CenterCVE-2026-344877.5 High
Injection axios Dependency in Jira Service Management Data CenterCVE-2026-420357.4 High
Injection axios Dependency in Jira Service Management Data CenterCVE-2026-420337.4 High
Information Disclosure org.apache.tomcat:tomcat-websocket Dependency in Jira Service Management Data Center and ServerCVE-2026-424987.3 High
RCE (Remote Code Execution) axios Dependency in Jira Service Management Data CenterCVE-2026-444957 High


Frequently Asked Questions:

  • Why is my Feature Version not listed in a Fixed Version? You may be using an unsupported version and need to patch to the latest version or Long-Term Support (LTS) version.

  • What are the most up-to-date Data Center product versions? You can always check the software download portal or visit the product-specific download pages.
  • I am using an LTS, why is it not listed in the Fixed Versions? Your LTS version may not have been updated yet or a backported fix may not have been feasible. Please see our Security Bug Fix Policy for more information. We recommend upgrading your products to the latest versions. For the latest fixed versions, visit the release notes linked in the vulnerability table.

  • Questions about the bulletin, have feedback? Let us know! Read more about our bulletins and feel free to contribute feedback on our latest Community Post


To search for CVEs or check your products versions for disclosed vulnerabilities, check the Vulnerability Disclosure Portal.

最終更新日 2026 年 6 月 16 日

この内容はお役に立ちましたか?

はい
いいえ
この記事についてのフィードバックを送信する
Powered by Confluence and Scroll Viewport.