Atlassian fixes 37 high-severity vulnerabilities in its December update
Atlassian's December 2025 security bulletin covers 37 high-severity vulnerabilities and nine critical third-party vulnerabilities. Several products include fixes for CVE-2025-66516, a critical Apache Tika vulnerability with a CVSS score of 10.0. Atlassian's security team assesses that the flaw does not present the same critical risk in its products, as the dependency does not support the known exploitation path. The vulnerabilities listed in the bulletin are fixed in newer releases published over the past month.
What this means for your organisation
Jira and Confluence often hold what amounts to the organisation's memory: architecture, contracts, personal data and incident history. Where the services run on your own infrastructure, patching is your responsibility. Note in particular that critical third-party vulnerabilities must be followed up in every system using the same component, not only in the Atlassian products.
Berigo recommends
- Schedule updates for self-hosted Atlassian installations to an agreed deadline, and record the decision.
- Map where Apache Tika is used elsewhere in your estate and assess CVE-2025-66516 there.
- Ensure Jira and Confluence are not directly reachable from the internet without access control.
- Establish a fixed monthly routine for reviewing supplier security bulletins.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch