Atlassian fixes 38 vulnerabilities across Jira, Confluence and Bitbucket

Atlassian has published its security bulletin for April 2026, covering seven critical and 31 high severity vulnerabilities in the Data Center and Server editions of Bamboo, Bitbucket, Confluence, Jira and Jira Service Management. CVSS ratings range from 7.1 to 10, though the highest not originating in a third-party dependency is 8.8. Atlassian recommends updating to the latest version or to one of the fixed versions listed in the bulletin.

What this means for your organisation

Self-hosted Atlassian products usually sit close to what matters: project documentation, customer cases, source code and internal procedures. Confluence vulnerabilities have historically been among the first to see broad exploitation after disclosure, and organisations running their own instances have no vendor to apply the update for them. The volume in this bulletin means the work should be planned as a job, not squeezed into a spare hour.

Berigo recommends

  • Set a specific maintenance window for the Atlassian update rather than waiting for the next routine cycle.
  • Prioritise instances reachable from the internet, and consider putting them behind authentication until updated.
  • Take a backup and verify that it restores before updating production instances.
  • Establish who owns each instance internally; ownerless Confluence installations are a common source of backlog.

Source

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch