Security Bulletin - June 16 2026
June 2026 Security Bulletin
The vulnerabilities reported in this Security Bulletin include 76 high-severity vulnerabilities and 24 critical-severity third-party vulnerabilities, which have been fixed in new versions of our products released in the last month.
CVEs reported in monthly Security Bulletins have been assessed as presenting a non-critical risk to Atlassian customers. Atlassian issues Critical Security Advisories for vulnerabilities that pose an immediate critical risk based on how our products actually use the affected components outside of our monthly Security Bulletin schedule as necessary.
Vulnerabilities are discovered through our Bug Bounty program, pen-testing processes, and third-party library scans.
The increase in reported vulnerabilities this month is attributed to externally coordinated security research and patching activity across several widely-used open-source libraries. These upstream events are reflected in our dependency scanning results and do not indicate a change in Atlassian's own security posture.
INSTRUCTIONS
To fix all the vulnerabilities impacting your product(s), Atlassian recommends patching your instances to the latest version or one of the Fixed Versions for each product below. The listed Fixed Versions for each product are current as of June 16, 2026 (date of publication); visit the linked product Release Notes for the most up-to-date versions.
To search for CVEs or check your product versions for disclosed vulnerabilities, check the Vulnerability Disclosure Portal.
Frequently Asked Questions:
Why is my Feature Version not listed in a Fixed Version? You may be using an unsupported version and need to patch to the latest version or Long-Term Support (LTS) version.
- What are the most up-to-date Data Center product versions? You can always check the software download portal or visit the product-specific download pages.
I am using an LTS, why is it not listed in the Fixed Versions? Your LTS version may not have been updated yet or a backported fix may not have been feasible. Please see our Security Bug Fix Policy for more information. We recommend upgrading your products to the latest versions. For the latest fixed versions, visit the release notes linked in the vulnerability table.
Questions about the bulletin, have feedback? Let us know! Read more about our bulletins and feel free to contribute feedback on our latest Community Post
To search for CVEs or check your products versions for disclosed vulnerabilities, check the Vulnerability Disclosure Portal.