Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY8 SECURITY RECORDS

Atlassian

Bamboo Data Center

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-21589 5 Oct 2026 Bamboo Data Center: All other versions; Bitbucket Data Center: All other versions; Confluence Data Center: All other versions; Crowd Data Center: All other versions; Crucible Data Center: All other versions; Fisheye Data Center: All other versions; Jira Service Management Data Center: All other versions; Jira Software Data Center: All other versions Bamboo Data Center: Patch version 10.2.24 and later, Patch version 12.1.12 and later; Bitbucket Data Center: Patch version 10.2.8 and later, Patch version 10.5.1 and later, Patch version 9.4.26 and later; Confluence Data Center: Patch version 10.2.19 and later, Patch version 9.2.26 and later; Crowd Data Center: Patch version 7.2.4 and later, Patch version 7.1.7 and later, Patch version 7.0.3 and later, Patch version 6.3.7 and later; Crucible Data Center: Patch version 4.9.15 and later; Fisheye Data Center: Patch version 4.9.15 and later; Jira Service Management Data Center: Patch version 11.3.12 and later, Patch version 10.3.26 and later, Patch version 5.12.40 and later; Jira Software Data Center: Patch version 11.3.12 and later, Patch version 10.3.26 and later, Patch version 9.12.40 and later Update reference ↗
CVE-2026-21584 18 Aug 2026 12.1.0 to 12.1.9; 12.0.0 to 12.0.2; 11.0.0 to 11.0.8; 10.2.0 to 10.2.21; 10.1.0 to 10.1.1; 10.0.0 to 10.0.3 12.1.10; 10.2.22 Update reference ↗
CVE-2026-21571 21 Apr 2026 12.1.0 to 12.1.3; 12.0.0 to 12.0.2; 11.0.0 to 11.0.8; 10.2.0 to 10.2.16; 10.1.0 to 10.1.1; 10.0.0 to 10.0.3; 9.6.2 to 9.6.24 12.1.6; 10.2.18; 9.6.25 Update reference ↗
CVE-2026-21570 17 Mar 2026 12.1.0 to 12.1.2; 12.0.0 to 12.0.2; 11.0.0 to 11.0.8; 10.2.0 to 10.2.15; 10.1.0 to 10.1.1; 10.0.0 to 10.0.3; 9.6.1 to 9.6.23 12.1.3; 10.2.16; 9.6.24 Update reference ↗
CVE-2024-21689 20 Aug 2024 9.6.0 to 9.6.4; 9.5.0 to 9.5.4; 9.4.0 to 9.4.4; 9.3.0 to 9.3.6; 9.2.1 to 9.2.16; 9.1.0 to 9.1.3 9.6.5; 9.2.17 Update reference ↗
CVE-2024-21687 16 Jul 2024 9.6.0 to 9.6.3; 9.5.0 to 9.5.4; 9.4.0 to 9.4.4; 9.3.0 to 9.3.6; 9.2.1 to 9.2.15; 9.1.0 to 9.1.3 9.6.4; 9.2.16 Update reference ↗
CVE-2023-22516 21 Nov 2023 >= 8.1.0; >= 8.1.1; >= 8.1.10; >= 8.1.11; >= 8.1.12; >= 8.1.2; >= 8.1.3; >= 8.1.4 < 8.1.0; >= 9.2.7; >= 9.3.4 Update reference ↗
CVE-2023-22506 18 Jul 2023 >= 8.0.0 < 8.0.0; >= 9.2.3; >= 9.3.1 Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.