PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-21577 Atlassian CVE debrief

A High severity DoS (Denial of Service) vulnerability was introduced in multiple versions of Confluence Data Center. This vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to cause a resource to be unavailable for its intended users by temporarily or indefinitely disrupting services of a host connected to a network. The vulnerability affects Confluence Data Center versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0.

Vendor
Atlassian
Product
Confluence Data Center
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-22
Advisory published
2026-07-21
Advisory updated
2026-07-22

Who should care

Confluence Data Center customers and administrators should be aware of this vulnerability and take necessary actions to upgrade to a fixed version. Operators, platform teams, vulnerability management teams, and security teams should review the affected scope and apply vendor guidance.

Technical summary

The vulnerability was introduced in Confluence Data Center versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0, and 10.2.0. Atlassian recommends upgrading to the latest version or one of the specified supported fixed versions: Confluence Data Center 9.2 (upgrade to a release greater than or equal to 9.2.17) or Confluence Data Center 10.2 (upgrade to a release greater than or equal to 10.2.7).

Defensive priority

High priority should be given to upgrading Confluence Data Center instances to a fixed version, as this vulnerability allows an authenticated attacker to cause a denial of service.

Recommended defensive actions

  • Upgrade Confluence Data Center to the latest version.
  • If unable to upgrade to the latest version, upgrade to one of the specified supported fixed versions: Confluence Data Center 9.2 (upgrade to a release greater than or equal to 9.2.17) or Confluence Data Center 10.2 (
  • Review and apply the recommended fixes as per the release notes.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The vulnerability was reported via Atlassian's Penetration Testing program. The CVE record was published on 2026-07-21T18:16:57.327Z and modified on 2026-07-22T19:16:59.073Z. Evidence is limited to public sources and penetration testing results. Defenders should verify affected scope and apply vendor guidance.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T18:16:57.327Z and has not been modified since then.