<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — Atlassian</title><description>Vulnerabilities in Atlassian Confluence, Jira, and Bitbucket — frequent ransomware-precursor targets due to the sensitive internal documentation they host. Combined article + CVE feed for the Atlassian beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>CVE-2019-11580 — Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2019-11580/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-11580/</guid><description>Atlassian Crowd and Crowd Data Center contain a remote code execution vulnerability resulting from a pdkinstall development plugin being incorrectly enabled in release builds.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Atlassian</category><category>critical</category><category>cve</category></item><item><title>CVE-2019-11581 — Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2019-11581/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-11581/</guid><description>Atlassian Jira Server and Data Center contain a server-side template injection vulnerability which can allow for remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Atlassian</category><category>critical</category><category>cve</category></item><item><title>CVE-2019-3396 — Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2019-3396/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-3396/</guid><description>Atlassian Confluence Server and Data Center contain a server-side template injection vulnerability that may allow an attacker to achieve path traversal and remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Atlassian</category><category>critical</category><category>cve</category></item><item><title>CVE-2019-3398 — Atlassian Confluence Server and Data Center Path Traversal Vulnerability</title><link>https://0daynews.com/cve/cve-2019-3398/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-3398/</guid><description>Atlassian Confluence Server and Data Center contain a path traversal vulnerability in the downloadallattachments resource that may allow a privileged, remote attacker to write files. Exploitation can lead to remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Atlassian</category><category>high</category><category>cve</category></item><item><title>CVE-2021-26084 — Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2021-26084/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-26084/</guid><description>Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Atlassian</category><category>critical</category><category>cve</category></item><item><title>CVE-2021-26085 — Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability</title><link>https://0daynews.com/cve/cve-2021-26085/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-26085/</guid><description>Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Atlassian</category><category>medium</category><category>cve</category></item><item><title>CVE-2021-26086 — Atlassian Jira Server and Data Center Path Traversal Vulnerability</title><link>https://0daynews.com/cve/cve-2021-26086/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-26086/</guid><description>Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Atlassian</category><category>medium</category><category>cve</category></item><item><title>CVE-2022-26134 — Atlassian Confluence OGNL Injection Remote Code Execution</title><link>https://0daynews.com/cve/cve-2022-26134/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-26134/</guid><description>An unauthenticated OGNL (Object-Graph Navigation Language) injection vulnerability in Atlassian Confluence Server and Data Center allows remote code execution on any accessible Confluence instance, with no authentication required.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Atlassian</category><category>critical</category><category>cve</category></item><item><title>CVE-2022-26138 — Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability</title><link>https://0daynews.com/cve/cve-2022-26138/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-26138/</guid><description>Atlassian Questions For Confluence App has hard-coded credentials, exposing the username and password in plaintext. A remote unauthenticated attacker can use these credentials to log into Confluence and access all content accessible to users in the confluence-users group.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Atlassian</category><category>critical</category><category>cve</category></item><item><title>CVE-2022-36804 — Atlassian Bitbucket Server and Data Center Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2022-36804/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-36804/</guid><description>Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where an attacker with access to a public Bitbucket repository, or with read permissions to a private one, can execute code by sending a malicious HTTP request.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Atlassian</category><category>high</category><category>cve</category></item><item><title>CVE-2023-22515 — Atlassian Confluence Data Center and Server Broken Access Control</title><link>https://0daynews.com/cve/cve-2023-22515/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-22515/</guid><description>A broken-access-control vulnerability in Atlassian Confluence Data Center and Server allows a remote, unauthenticated attacker to create unauthorized Confluence administrator accounts and gain full access to affected instances.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Atlassian</category><category>critical</category><category>cve</category></item><item><title>CVE-2023-22518 — Atlassian Confluence Data Center and Server Improper Authorization Vulnerability</title><link>https://0daynews.com/cve/cve-2023-22518/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-22518/</guid><description>Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Atlassian</category><category>critical</category><category>cve</category></item><item><title>CVE-2023-22527 — Atlassian Confluence Data Center and Server Template Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2023-22527/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-22527/</guid><description>Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Atlassian</category><category>critical</category><category>cve</category></item><item><title>CVE-2023-22515: Three Years of Confluence Exploitation</title><link>https://0daynews.com/articles/2026-07-23-confluence-cve-2023-22515-three-years-kilobaud/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-23-confluence-cve-2023-22515-three-years-kilobaud/</guid><description>CVE-2023-22515 gave unauthenticated attackers Confluence admin access. Nearly three years on, EPSS sits at 0.99 — unpatched installs remain active targets.</description><pubDate>Thu, 23 Jul 2026 23:00:00 GMT</pubDate><category>Atlassian</category><category>article</category></item><item><title>The Confluence Bug That Became a Ransomware Precursor</title><link>https://0daynews.com/articles/2026-07-03-confluence-ognl-injection-cve-2022-26134/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-03-confluence-ognl-injection-cve-2022-26134/</guid><description>CVE-2022-26134 gave unauthenticated attackers remote code execution on any exposed Confluence instance — and became a go-to foothold for ransomware operators within days of disclosure.</description><pubDate>Fri, 03 Jul 2026 15:30:00 GMT</pubDate><category>Atlassian</category><category>article</category></item></channel></rss>