Vulnerability Disclosure Portal
The Vulnerability Disclosure Portal is a central hub for information about disclosed vulnerabilities in any of our products. It is updated monthly with the release of each Security Bulletin and provides an easy way to search and access data from previous bulletins.
Portal data and filtering capabilities are also available through our Security Vulnerability API for customers who wish to reach this data programmatically.

Vulnerability Disclosure Portal, Security at Atlassian: Vulnerabilities
More details can be found by clicking on any of the CVEs.

FAQs
What types of vulnerabilities will be included in the Security Bulletin?
Security Bulletin disclosures include unique critical and high-severity vulnerabilities as well as dependency vulnerabilities, for our server and DC products.
Is there a Security Bulletin for Cloud customers?
No, the Security Bulletin is for server and DC products only. We are able to seamlessly patch Cloud vulnerabilities without any action required on the part of the customer. For information on Atlassian cloud security, see our Security page.
What do customers need to do when a Security Bulletin is released?
Upgrading to new versions in a timely manner is an important step in keeping your Atlassian server and DC products secure, and we encourage customers to keep versions current. Though we will continue to issue Critical Security Advisories for vulnerabilities requiring immediate action, our goal with the Security Bulletin is to issue non-critical updates that can be supported on a regular maintenance schedule.
Is this change due to an increase in the number of vulnerabilities in Atlassian products?
No, the Security Bulletin and Portal are an enhancement to our ability to disclose fixed vulnerabilities, and do not reflect any changes in our processes to identify and fix them. The types of fixed vulnerabilities you will see in the new disclosures were previously fixed in released product versions. With this new monthly cadence, we’re able to offer greater transparency into the list of vulnerabilities mitigated under each new version (not just the most pressing) and encourage customers to support security best practices with a regular maintenance schedule. Atlassian will continue to issue Critical Security Advisories for vulnerabilities requiring immediate action.
When will the next bulletin be released?
The next bulletin will be released on Aug 15, 2023, you will be able to find it here.