Security Update Advisory for Atlassian Products

Security Update Advisory for Atlassian Products

Overview

Security updates addressing vulnerabilities in Atlassian products have been released. Users of the affected products should update to the latest version.

Affected Products and Vulnerabilities

  • Sourcetree for Mac and Sourcetree for Windows.
    • CVE-2026-21575: Remote code execution vulnerability.
    • Affected versions: 3.4.11 Through 3.4.12.
    • Fixed version: 3.4.13.
  • Confluence Data Center and Server.
    • CVE-2026-21577: Denial-of-service vulnerability.
    • CVE-2026-21579: Information disclosure vulnerability.
    • Affected versions: 7.9.26 Through 7.19.30 (LTS), 8.5.14 Through 8.5.31 (LTS), 8.9.5 Through 8.9.8, 9.0.1 Through 9.0.3, 9.1.0 Through 9.1.1, 9.2.0 Through 9.2.21 (LTS), 9.3.1 Through 9.3.2, 9.4.0 Through 9.4.1, 9.5.1 Or higher, 9.5.4 Or lower; 10.0.2 Or higher, 10.0.3 Or lower; 10.1.0 Or higher, 10.1.2 Or lower; 10.2.0 Or higher, 10.2.13 (LTS) or lower.
    • Fixed versions: 10.2.14 (LTS), 9.2.22 (LTS).

Summary

This security update addresses remote code execution, denial-of-service, and information disclosure vulnerabilities identified in Atlassian’s Sourcetree and Confluence product families. Organizations using these products should update to the latest patch versions announced.