Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
AUTOMATICALLY VERIFIEDOFFICIAL VENDOR SOURCECOLLECTED 12 SEP 2026

Atlassian · AUTOMATIC DISCOVERY

Confluence 10.0

Confluence is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Evidence status

This record passed BlackTree's automatic primary-source checks with a confidence score of 96. It is returned for operational research without requiring routine manual approval. Confirm edition and deployment applicability before acting.

Product overview

Confluence is tracked by BlackTree as a server-side software product. Its lifecycle page separates release identity, maintenance and security boundaries using the publisher's registered source.

Main capabilities

  • Networked or application service delivery
  • Administrative and operational interfaces
  • Versioned maintenance and security updates

Typical use

Used to provide application, infrastructure or operational services to other systems and users.

Deployment

Deployed on servers, virtual machines, containers or managed infrastructure.

This category-level context is generated from the registered product identity. Confirm exact product capabilities on the publisher's page .

Collected lifecycle data

ProductConfluence
Release10.0
End of Support5 August 2027
Date precisionDay

Known exploited vulnerabilities

Catalogue updated 11 Sep 2026

These are product-family matches in the CISA Known Exploited Vulnerabilities catalogue. Confirm the affected product version in the vendor advisory.

CVE-2023-22527Added 24 Jan 2024

Atlassian Confluence Data Center and Server Template Injection Vulnerability

Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that can lead to remote code execution.

Atlassian · Confluence Data Center and ServerRansomware use: Known

CISA entry
CVE-2023-22518Added 7 Nov 2023

Atlassian Confluence Data Center and Server Improper Authorization Vulnerability

Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality since the attacker cannot exfiltrate any data.

Atlassian · Confluence Data Center and ServerRansomware use: Known

CISA entry
CVE-2023-22515Added 5 Oct 2023

Atlassian Confluence Data Center and Server Broken Access Control Vulnerability

Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence.

Atlassian · Confluence Data Center and ServerRansomware use: Known

CISA entry
CVE-2022-26138Added 29 Jul 2022

Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability

Atlassian Questions For Confluence App has hard-coded credentials, exposing the username and password in plaintext. A remote unauthenticated attacker can use these credentials to log into Confluence and access all content accessible to users in the confluence-users group.

Atlassian · ConfluenceRansomware use: Unknown

CISA entry
CVE-2022-26134Added 2 Jun 2022

Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability

Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution.

Atlassian · Confluence Server/Data CenterRansomware use: Known

CISA entry
CVE-2021-26085Added 28 Mar 2022

Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability

Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.

Atlassian · Confluence ServerRansomware use: Known

CISA entry

Showing the 6 most recently added of 9 product-family matches.

Package vulnerability advisories

OSV advisories are matched through the registered package URL. A package-family match does not prove that the installed release is affected. Check the affected and fixed versions before remediation.

No package advisories have been linked for this product identity.

This is not evidence that the product has no vulnerabilities.

Source evidence

PRIMARYPartial

Bamboo official lifecycle source

Confluence | 10.2 (EOS date: 2 December 2027) LONG TERM SUPPORT | 10.1 (EOS date: 7 October 2027) | 10.0 (EOS date: 5 August 2027) | 9.5 (EOS date: 4 June 2027) | 9.4 (EOS date: 1 Apr 2027) | 9.3 (EOS date: 4 Feb 2027)

Official vendor lifecycle or product-change property. Extracted records require human review.

First collected 12 Sep 2026 · Last collected 12 Sep 2026 · Review state accepted

Open official vendor source