Atlassian A.I CyberSecurity Scoring
Atlassian
Company Information
Website:https://atlassian.com/
Employees number:16,931
Number of followers:2,601,927
NAICS:5112
Industry Type:Software Development
Homepage:atlassian.com
Atlassian Risk Score (AI oriented)
Between 750 and 799
AtlassianSoftware Development
Updated:
30/09/2026
30/09/2026
755/1000
Fair
Baa
Atlassian Global Score (TPRM)
xxxx
AtlassianSoftware Development
Score locked

AtlassianFair
Current Score
755Baa (FAIR)
01000
12 incidents
-5.83 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
755
SEPTEMBER 2026
754
AUGUST 2026
756
Vulnerability
10 Aug 2026 • Atlassian
Atlassian: Atlassian Rovo AI Vulnerability Lets Attackers Steal Enterprise Data With a Single Click
RovoBlast: Critical Atlassian Rovo AI Vulnerability Exposes Enterprise Data via Malicious Links
752
CRITICAL-4
ATL1786359965
RovoBlast: Critical Atlassian Rovo AI Vulnerability Exposes Enterprise Data via Malicious Links
Security researchers at Varonis Threat Labs have uncovered RovoBlast, a severe vulnerability in Atlassian’s Rovo AI assistant that enables attackers to extract sensitive enterprise data through a single malicious link. The flaw exploits Rovo’s handling of URL-supplied prompts, allowing threat actors to inject malicious instructions into an authenticated user’s AI session without requiring account compromise or permission bypasses.
The attack leverages a parameter-to-prompt (P2P) weakness, where Rovo treats text embedded in a URL (via the `rovoChatPrompt` parameter) as a pre-filled chat instruction within a trusted session. A crafted link such as `https://home.atlassian.com/chat?rovoChatPathway=chat&rovoChatPrompt=<malicious_prompt>` can trigger the assistant to execute attacker-controlled commands when clicked by a logged-in user.
Rovo, designed as an AI layer across Atlassian products (Jira, Confluence, Bitbucket) and external platforms (Slack, Microsoft 365, Google Workspace, databases, and web resources), operates under the permissions of the authenticated user. This means malicious prompts can search, summarize, or exfiltrate data while appearing as legitimate AI-assisted workflows. The ResearchAgent feature is particularly concerning, as it can perform multi-step research, navigate websites, and potentially chain actions to retrieve and transmit sensitive information all from a single prompt.
Unlike traditional prompt-injection attacks, RovoBlast does not require elaborate jailbreaks or repeated inputs, making it harder for defenders to detect. The vulnerability underscores the risks of AI assistants processing untrusted content while holding broad data access. Organizations are advised to restrict Rovo’s integrations, disable unnecessary automation features, and monitor AI logs for unusual behavior to mitigate exposure. The discovery highlights a growing security challenge: AI assistants with expansive permissions and external connectivity can become low-friction vectors for data exfiltration.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JULY 2026
754
JUNE 2026
753
MAY 2026
754
Vulnerability
01 May 2026 • Atlassian
Atlassian and 1C Company: Feral Wolf Ransomware Attacks Exploit Atlassian Confluence and Misconfigured 1C Systems
Feral Wolf Ransomware Campaign Exploits Exposed Business Software in Russian Organizations
751
CRITICAL-3
ATL1C-1789741437
Feral Wolf Ransomware Campaign Exploits Exposed Business Software in Russian Organizations
A recent ransomware campaign by the threat group Feral Wolf has targeted Russian organizations across retail, construction, manufacturing, and IT sectors from May to August 2026, leveraging exposed business software and weak server configurations to infiltrate corporate networks. The attackers deployed GenieLocker ransomware after gaining access through vulnerable systems, demonstrating how a single overlooked internet-facing service can lead to a full-scale breach.
Security firm BI.ZONE uncovered the intrusions, tracing attack paths through unpatched Atlassian Confluence installations, poorly secured 1C:Enterprise clusters, and contractor environments. In one case, Feral Wolf exploited CVE-2023-22515 on a publicly accessible Confluence server running in a Docker container, creating an admin account to establish a foothold. From there, they moved laterally by compromising a PostgreSQL service with weak credentials, escalating access to the underlying host.
The group also abused misconfigured 1C:Enterprise server clusters, exploiting unprotected management services and debug modes to execute arbitrary commands. Their tactics included custom backdoors (MQTTDoor and MatrixDoor), which communicated via MQTT and Matrix protocols, blending malicious traffic with legitimate network activity. Additionally, they used proxy tools to tunnel traffic through Remote Desktop Protocol (RDP) sessions, further evading detection.
Post-compromise, Feral Wolf employed credential theft techniques, extracting memory from Windows systems using legitimate utilities, and attempted to erase forensic evidence with PowerShell scripts. The campaign highlights the risks of unpatched collaboration platforms, exposed database services, and weak authentication controls, emphasizing the need for network segmentation, log monitoring, and rapid patching to disrupt multi-stage ransomware attacks.
Indicators of Compromise (IoCs) associated with the campaign include:
- IPs: `45.151.45[.]31` (Confluence intrusion), `46.166.79[.]31` (PostgreSQL server)
- Domains: `broker.hivemq[.]com` (MQTT broker), `meet.element[.]tw` (Matrix homeserver)
- Tools: `PrintSpoofer64.exe`, `nyx.ps1`, `fscan`, and GenieLocker ransomware samples
- Hashes: Multiple SHA-256 values for backdoors and malware (e.g., `MQTTDoor`, `MatrixDoor`)
The investigation underscores that ransomware incidents often stem from chained vulnerabilities, combining known exploits, credential abuse, and covert communication channels to evade detection before encryption.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
APRIL 2026
757
Vulnerability
21 Apr 2026 • Atlassian
Atlassian: Critical Bamboo Data Center and Server Vulnerability Enables Command Injection Attacks
Critical OS Command Injection Flaw in Atlassian Bamboo Puts CI/CD Pipelines at Risk
754
CRITICAL-3
ATL1776868681
Critical OS Command Injection Flaw in Atlassian Bamboo Puts CI/CD Pipelines at Risk
Atlassian disclosed a critical security vulnerability (CVE-2026-21571) in Bamboo Data Center and Server, allowing remote attackers to execute arbitrary operating system commands. The flaw, assigned a CVSS score of 9.4, was published on April 21, 2026, as part of Atlassian’s monthly Security Bulletin.
The vulnerability affects multiple versions of Bamboo, including 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0. It stems from a third-party dependency but remains classified as critical due to its potential impact. Exploitation requires low-level authentication and no user interaction, making it a high-risk threat for enterprise environments.
Successful attacks could enable threat actors to inject malicious code into CI/CD pipelines, compromising software supply chains, accessing sensitive data, or disrupting system operations. Given Bamboo’s role in automating build and deployment workflows, unpatched systems pose a significant risk to development environments.
Atlassian has released patched versions (12.1.6 (LTS), 10.2.18 (LTS), and 9.6.25) to mitigate the flaw. Organizations unable to upgrade immediately are advised to review Atlassian’s Vulnerability Disclosure Portal for mitigation steps, including monitoring authentication logs and auditing CI/CD pipelines for unauthorized changes.
The April 2026 Security Bulletin also addressed 37 additional vulnerabilities, including a CVSS 10.0 cross-site scripting flaw and a remote code execution issue in other Atlassian products like Jira, Confluence, and Bitbucket.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
759
Vulnerability
30 Mar 2026 • Atlassian
Atlassian: Stored XSS Vulnerability in Jira Work Management Could Enable Full Organization Takeover
Critical Stored XSS Vulnerability in Atlassian Jira Enables Full Organization Takeover
756
CRITICAL-3
ATL1774866325
Critical Stored XSS Vulnerability in Atlassian Jira Enables Full Organization Takeover
Security researchers at SnapSec recently disclosed a severe stored Cross-Site Scripting (XSS) vulnerability in Atlassian’s Jira Work Management, a widely used platform for project tracking and task management. The flaw, stemming from inadequate input validation in a low-risk settings menu, allows attackers with limited administrative permissions to execute a full organization takeover.
### Vulnerability Details
The issue resides in Jira’s custom priority settings, where administrators can define task importance levels (e.g., high, medium, low). While editing these priorities, users can specify an Icon URL a field that, if manipulated, could inject malicious JavaScript. Researchers demonstrated that a Product Admin a role with restricted but sufficient permissions could embed a payload in the URL (e.g., `https://google.com?name=</script><script>alert(0)</script>`). Due to missing backend validation and output encoding, the script was stored in the database and executed when a Super Admin accessed the priorities configuration page.
### Exploitation & Impact
The attack leverages stored XSS, meaning no victim interaction (e.g., clicking a link) is required. Once a Super Admin loads the compromised page, the malicious script executes in their browser, operating within a highly privileged administrative context. In SnapSec’s proof-of-concept, the payload silently sent a system invitation to an attacker-controlled account, granting them full access to Jira, Confluence, and other Atlassian products. This enabled unauthorized project creation, modification, and deletion effectively seizing control of the entire organization.
### Key Takeaways
- The vulnerability exposes a critical gap in input validation, even in mature enterprise platforms.
- Partially privileged roles (e.g., Product Admins) can escalate to full administrative control if access controls are not rigorously audited.
- The incident underscores the need for strict backend validation and output encoding across all configuration panels, regardless of perceived risk.
Atlassian has since addressed the flaw, but the discovery serves as a reminder that overlooked administrative features can become high-impact attack vectors.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
FEBRUARY 2026
758
JANUARY 2026
759
Vulnerability
01 Jan 2026 • Atlassian
Atlassian: Bamboo Data Center and Server Vulnerability Enables Remote Code Execution
Atlassian Patches High-Severity RCE Vulnerability in Bamboo Data Center
755
CRITICAL-4
ATL1773995178
Atlassian Patches High-Severity RCE Vulnerability in Bamboo Data Center
Atlassian has addressed a high-severity remote code execution (RCE) vulnerability, CVE-2026-21570, affecting its Bamboo Data Center application. The flaw, discovered internally through Atlassian’s security auditing program, poses significant risks to enterprise CI/CD environments, where Bamboo serves as a critical hub for automated builds, testing, and deployment.
With a CVSS 4.0 score of 8.6, the vulnerability allows authenticated attackers with elevated privileges to execute arbitrary code remotely on affected servers. Exploitation could lead to full system compromise, enabling threat actors to manipulate source code, exfiltrate sensitive build secrets, or disrupt software development operations potentially facilitating devastating supply chain attacks.
The flaw impacts multiple Bamboo Data Center versions, including:
- 9.6.x (9.6.0–9.6.23)
- 10.0.0, 10.1.0, 10.2.0
- 11.0.0, 11.1.0
- 12.x (12.0.0–12.1.2)
Atlassian has released patches to mitigate the issue, urging administrators to upgrade immediately:
- 9.6.x → 9.6.24 or later
- 10.2.x → 10.2.16
- 12.1.x → 12.1.3 or later
Patched versions are available via the Atlassian download center. Organizations running affected deployments are advised to apply updates to secure their build infrastructure.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2025
777
Cyber Attack
28 Dec 2025 • Atlassian
Canva, Adyen, Atlassian, HubSpot, Epic Games, Moderna, GameStop, ZoomInfo, WeWork, Halliburton, Betterment, Sonos and Telstra: Over 100 Organizations Targeted in ShinyHunters Phishing Campaign
ShinyHunters-Linked Cybercrime Campaign Targets Over 100 Major Organizations
759
CRITICAL-18
CANADYATLHUBEPIMODGAMZOOWEWHALBETSONTEL1769527593
ShinyHunters-Linked Cybercrime Campaign Targets Over 100 Major Organizations
A recent cybercrime campaign attributed to the ShinyHunters group has targeted at least 100 organizations across multiple sectors, including software, finance, healthcare, and energy, according to cybersecurity firm Silent Push. Over the past 30 days, threat actors registered fake domains impersonating high-profile companies such as Atlassian, Adyen, Canva, Epic Games, HubSpot, Moderna, ZoomInfo, GameStop, WeWork, Halliburton, Sonos, and Telstra.
The attackers employed voice phishing (vishing) tactics to compromise single sign-on (SSO) accounts, particularly those using Okta and other identity platforms. Using specialized phishing kits, they intercepted credentials and manipulated victims into bypassing multi-factor authentication (MFA) by convincing them to approve push notifications or submit one-time passcodes (OTPs). Okta described the attacks as involving real-time session orchestration, where threat actors guided victims through the authentication process via verbal instructions.
While Silent Push identified the infrastructure used in the campaign, it remains unclear whether the attacks successfully breached any systems. However, ShinyHunters has claimed responsibility for data breaches at companies like Betterment, Crunchbase, and SoundCloud, all of which confirmed incidents. The group allegedly stole millions of records from these organizations as part of the Okta SSO vishing campaign.
Silent Push attributes the campaign to Scattered LAPSUS$ Hunters, a collective formed last year by members of Lapsus$, Scattered Spider, and ShinyHunters, based on observed tactics, techniques, and procedures (TTPs). The incident follows recent warnings from Google and others about rising vishing and phishing attacks targeting identity platforms.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2025
776
OCTOBER 2023
753
Vulnerability
05 Oct 2023 • Atlassian
Atlassian: Feral Wolf ransomware targets Russian firms using Confluence flaws
Feral Wolf Ransomware Group Exploits Confluence Flaws to Target Russian Organizations
750
CRITICAL-3
ATL1790785602
Feral Wolf Ransomware Group Exploits Confluence Flaws to Target Russian Organizations
The Feral Wolf ransomware group has launched a campaign against Russian organizations, exploiting exposed Atlassian Confluence servers, misconfigured 1C:Enterprise systems, and compromised contractor credentials to deploy GenieLocker ransomware. The attacks leverage CVE-2023-22515, a critical Confluence vulnerability, as an initial entry point, followed by privilege escalation using CVE-2021-4034 and CVE-2026-31431.
Feral Wolf, a financially motivated threat actor, conducts extensive reconnaissance before establishing persistent access. The group employs anti-forensic tools to erase logs and uses MQTT, Matrix, and RDP-based tunnels to obscure command-and-control traffic. Weakly secured 1C configurations and stolen credentials further enable lateral movement, leading to data encryption, operational disruption, and prolonged recovery efforts.
The campaign underscores the risks of unpatched software and exposed administrative interfaces, particularly in enterprise environments. Organizations are advised to prioritize patching, enforce strong authentication, and restrict direct internet access to critical systems. The findings were reported by Smarter MSP.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2023
724
Vulnerability
16 Jun 2023 • Atlassian
Atlassian
Atlassian Confluence Cryptomining Campaign
721
CRITICAL-3
ATL000083124
Atlassian Confluence Data Center and Server versions were affected by a critical vulnerability identified as CVE-2023-22527, enabling threat actors to exploit the flaw for cryptomining campaigns. Due to the template injection vulnerability, remote attackers could execute arbitrary code, leading to unauthorized cryptocurrency mining using the organization's resources. This activity not only utilized the compromised infrastructure for mining but also had the potential to disrupt operations and financials through resource exhaustion and increase in operational costs. Atlassian released patches to address the issue, however, systems not updated remained at risk.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
FEBRUARY 2023
778
Data Leak
01 Feb 2023 • Atlassian
Atlassian
Atlassian Data Leak
718
HIGH-60
ATL195481023
Atlassian reveals a data leak that was brought on by the theft of employee login information that was then utilized to obtain data from a third-party vendor.
More than 13,200 entries make up the employee file that was uploaded online, and a brief inspection of the file suggests that it contains data on many current employees, including names, email addresses, work departments, and other details.
The threat actors obtained information from a third-party vendor using the employee login credentials they had stolen.
The business emphasized that the event had no impact on consumer or network data.
The business acknowledged the data breach and disclosed that Envoy, a startup that offers workplace management services to the Australian software giant, was the source of the leaked data.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2022
778
Vulnerability
01 Jun 2022 • Atlassian
Atlassian
Atlassian Confluence Server Zero-Day Vulnerability
774
CRITICAL-4
ATL23554622
Atlassian warned its customers that multiple threat groups are exploiting a Confluence Server zero-day vulnerability in its servers.
Any unauthenticated attackers can target its Confluence Server and Data Center by a critical vulnerability that can be exploited for remote code execution.
The company advised its users have been advised to prevent access to their Confluence servers from the internet, or simply disable these instances, as all supported versions of Confluence Server and Data Center are affected.
However, Atlassian expects fixes to become available soon.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
AUGUST 2021
777
Vulnerability
01 Aug 2021 • Atlassian
Atlassian
Confluence Server Webwork OGNL Injection Vulnerability
773
CRITICAL-4
ATL0214622
Atlassian discovered a vulnerability in its Confluence Server which they need to patch to remedy a Critical-rated flaw.
Confluence Server Webwork OGNL injection vulnerability could allow an authenticated user, or unauthenticated user, to execute arbitrary code on a Confluence Server or Data Center instance.
However, Atlassian's own Confluence Cloud was patched but other hosted Confluence offerings might be vulnerable.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
APRIL 2017
794
Data Leak
01 Apr 2017 • Atlassian
Atlassian
Atlassian HipChat Data Breach
745
MEDIUM-49
ATL116201123
Atlassian revealed that unidentified hackers gained access to a vast quantity of data from its group chat service HipChat by breaking into a cloud server owned by the business.
Although Atlassian did not disclose the identity of the prominent third-party software library that was utilised by its HipChat.com service, the business claims that attackers took advantage of a weakness in the library.
The business issued instructions on how to reset passwords to all users whose accounts were connected to HipChat and, as a precaution, invalidated the passwords on those accounts.
The organisation claims that although hashed passwords, email addresses, and names were accessible to hackers, no financial information was revealed.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Atlassian ??
What was Atlassian's A.I Rankiteo Cyber Score in September 2026 ??
What was Atlassian's A.I Rankiteo Cyber Score in August 2026 ??
What was Atlassian's A.I Rankiteo Cyber Score in July 2026 ??
What was Atlassian's A.I Rankiteo Cyber Score in June 2026 ??
What was Atlassian's A.I Rankiteo Cyber Score in May 2026 ??
What was Atlassian's A.I Rankiteo Cyber Score in April 2026 ??
What was Atlassian's A.I Rankiteo Cyber Score in March 2026 ??
What was Atlassian's A.I Rankiteo Cyber Score in February 2026 ??
What was Atlassian's A.I Rankiteo Cyber Score in January 2026 ??
What was Atlassian's A.I Rankiteo Cyber Score in December 2025 ??
What was Atlassian's A.I Rankiteo Cyber Score in November 2025 ??
What is the average per-incident point impact on Atlassian's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Atlassian ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Atlassian's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?