ENISA EUVD · EUVD-2026-38595Official EUVD mapping0 linked advisory records.
Official EUVD record ↗BSI · German · WID-SEC-2026-3595IBM QRadar SIEM: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um beliebigen Programmcode auszuführen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen und um Sicherheitsvorkehrungen zu umgehen.
Official advisory ↗BSI · German · WID-SEC-2026-3376Atlassian Bamboo, Bitbucket, Confluence, Fisheye/Crucible, Jira Software und Jira Service Management: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Bitbucket, Confluence, Fisheye/Crucible, Jira Software und Jira Service Management ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, serverseitige Request-Forgery-Angriffe (SSRF) durchzuführen, Cross-Site-Scripting-Angriffe zu starten, sensible Informationen offenzulegen, Daten zu manipulieren oder Denial-of-Service-Zustände herbeizuführen.
Official advisory ↗BSI · German · WID-SEC-2026-3043IBM QRadar SIEM: Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um Sicherheitsvorkehrungen zu umgehen, um seine Privilegien zu erhöhen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen und um beliebigen Programmcode auszuführen.
Official advisory ↗BSI · German · WID-SEC-2026-2923Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, und Jira): Mehrere SchwachstellenEin Angreifer kann mehrere Schwachstellen in Atlassian Bamboo, Atlassian Bitbucket, Atlassian Confluence, Atlassian Crucible, Atlassian Fisheye und Atlassian Jira ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu manipulieren, um einen Cross-Site Scripting Angriff durchzuführen, um einen SQL-Injection Angriff durchzuführen, und um Sicherheitsvorkehrungen zu umgehen.
Official advisory ↗BSI · German · WID-SEC-2026-2444Oracle Fusion Middleware: Mehrere SchwachstellenEin entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle Fusion Middleware ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.
Official advisory ↗BSI · German · WID-SEC-2026-2058FasterXML Jackson: Mehrere SchwachstellenEin entfernter, anonymer Angreifer kann mehrere Schwachstellen in FasterXML Jackson ausnutzen, um Schutzmechanismen und Autorisierungsregeln zu umgehen, Daten zu manipulieren, Informationen offenzulegen oder einen Denial-of-Service zu verursachen.
Official advisory ↗BSI · German · WID-SEC-2026-2867RealObjects PDFreactor: Mehrere Schwachstellen ermöglichen nicht spezifizierten AngriffEin Angreifer kann mehrere Schwachstellen in RealObjects PDFreactor ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen.
Official advisory ↗Cyber Security Agency of Singapore · English · CSA-SB-20260624Security Bulletin 24 June 2026The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 24 June 2026, published on 24 June 2026. Open the linked bulletin for the product, severity and reference information published in that issue.
Official advisory ↗INCIBE-CERT · Spanish · boletin-de-seguridad-de-atlassian-septiembre-de-2026Boletín de seguridad de Atlassian: septiembre de 2026:
4.9.14 recommended.
Jira Data Center and Server:
11.3.11 (LTS) recommended Data Center Only;
10.3.25 (LTS) Data Center Only.
Jira Service Management Data Center and Server:
11.3.11 (LTS) recommended Data Center Only;
10.3.25 (LTS) Data Center Only.
Detalle
Las vulnerabilidades críticas publicadas en este boletín pertenecen a componentes de terceros. Se trata de vulnerabilidades en dependencias que no pertenecen a Atlassian. La aplicación de estas dependencias por parte de Atlassian presenta un riesgo menor, no crítico, según la evaluación realizada.
A continuación, se detallan las vulnerabilidades de severidad alta que afectan a Atlassian:
CVE-2026-54512 : DoS (Denial of Service) en tools.jackson.core:jackson-databind.
CVE-2026-54513 : RCE (Remote Code Execution) en jackson-databind.
CVE-2026-45623 : Divulgación de información en postcss.
CVE-2026-73507 : DoS (Denial of Service) en io.netty:netty-codec.
CVE-2026-68763 : DoS (Denial of Service) en org.apache.tomcat:tomcat-coyote.
CVE-2026-73646 : File Inclusion en postcss.
CVE-2026-53404 : BASM (Broken Authentication & Session Management) en Apache Tomcat.
CVE-2026-55153 : DoS (Denial of Service) en com.mchange:mchange-commons-java.
CVE-2026-21582 : BASM (Broken Authentication & Session Management) en Bitbucket Data Center.
CVE-2026-4800 : RC
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1256Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-53391
Référence CVE CVE-2026-53392
https://www.cve.org/CVERecord?id=CVE-2026-53392
Référence CVE CVE-2026-53397
https://www.cve.org/CVERecord?id=CVE-2026-53397
Référence CVE CVE-2026-53399
https://www.cve.org/CVERecord?id=CVE-2026-53399
Référence CVE CVE-2026-53550
https://www.cve.org/CVERecord?id=CVE-2026-53550
Référence CVE CVE-2026-53606
https://www.cve.org/CVERecord?id=CVE-2026-53606
Référence CVE CVE-2026-53655
https://www.cve.org/CVERecord?id=CVE-2026-53655
Référence CVE CVE-2026-54371
https://www.cve.org/CVERecord?id=CVE-2026-54371
Référence CVE CVE-2026-54411
https://www.cve.org/CVERecord?id=CVE-2026-54411
Référence CVE CVE-2026-54512
https://www.cve.org/CVERecord?id=CVE-2026-54512
Référence CVE CVE-2026-54513
https://www.cve.org/CVERecord?id=CVE-2026-54513
Référence CVE CVE-2026-54514
https://www.cve.org/CVERecord?id=CVE-2026-54514
Référence CVE CVE-2026-54515
https://www.cve.org/CVERecord?id=CVE-2026-54515
Référence CVE CVE-2026-54516
https://www.cve.org/CVERecord?id=CVE-2026-54516
Référence CVE CVE-2026-54517
https://www.cve.org/CVERecord?id=CVE-2026-54517
Référence CVE CVE-2026-54518
https://www.cve.org/CVERecord?id=CVE-2026-54518
Référence CVE CVE-2026-54874
https://www.cve.org/CVERecord?id=CVE-2026-54874
Référence CVE CVE-2026-5588
https://www.cve.org/CVERecord?id=C
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1165Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-53669
Référence CVE CVE-2026-54171
https://www.cve.org/CVERecord?id=CVE-2026-54171
Référence CVE CVE-2026-54225
https://www.cve.org/CVERecord?id=CVE-2026-54225
Référence CVE CVE-2026-54264
https://www.cve.org/CVERecord?id=CVE-2026-54264
Référence CVE CVE-2026-54265
https://www.cve.org/CVERecord?id=CVE-2026-54265
Référence CVE CVE-2026-54284
https://www.cve.org/CVERecord?id=CVE-2026-54284
Référence CVE CVE-2026-54297
https://www.cve.org/CVERecord?id=CVE-2026-54297
Référence CVE CVE-2026-54399
https://www.cve.org/CVERecord?id=CVE-2026-54399
Référence CVE CVE-2026-54428
https://www.cve.org/CVERecord?id=CVE-2026-54428
Référence CVE CVE-2026-54512
https://www.cve.org/CVERecord?id=CVE-2026-54512
Référence CVE CVE-2026-54513
https://www.cve.org/CVERecord?id=CVE-2026-54513
Référence CVE CVE-2026-54514
https://www.cve.org/CVERecord?id=CVE-2026-54514
Référence CVE CVE-2026-54515
https://www.cve.org/CVERecord?id=CVE-2026-54515
Référence CVE CVE-2026-54516
https://www.cve.org/CVERecord?id=CVE-2026-54516
Référence CVE CVE-2026-54517
https://www.cve.org/CVERecord?id=CVE-2026-54517
Référence CVE CVE-2026-54518
https://www.cve.org/CVERecord?id=CVE-2026-54518
Référence CVE CVE-2026-5516
https://www.cve.org/CVERecord?id=CVE-2026-5516
Référence CVE CVE-2026-55223
https://www.cve.org/CVERecord?id=CV
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-1094Multiples vulnérabilités dans les produits IBMecord?id=CVE-2026-54280
Référence CVE CVE-2026-54282
https://www.cve.org/CVERecord?id=CVE-2026-54282
Référence CVE CVE-2026-54283
https://www.cve.org/CVERecord?id=CVE-2026-54283
Référence CVE CVE-2026-54293
https://www.cve.org/CVERecord?id=CVE-2026-54293
Référence CVE CVE-2026-5435
https://www.cve.org/CVERecord?id=CVE-2026-5435
Référence CVE CVE-2026-54369
https://www.cve.org/CVERecord?id=CVE-2026-54369
Référence CVE CVE-2026-54370
https://www.cve.org/CVERecord?id=CVE-2026-54370
Référence CVE CVE-2026-54475
https://www.cve.org/CVERecord?id=CVE-2026-54475
Référence CVE CVE-2026-5450
https://www.cve.org/CVERecord?id=CVE-2026-5450
Référence CVE CVE-2026-54512
https://www.cve.org/CVERecord?id=CVE-2026-54512
Référence CVE CVE-2026-54513
https://www.cve.org/CVERecord?id=CVE-2026-54513
Référence CVE CVE-2026-54514
https://www.cve.org/CVERecord?id=CVE-2026-54514
Référence CVE CVE-2026-54515
https://www.cve.org/CVERecord?id=CVE-2026-54515
Référence CVE CVE-2026-55153
https://www.cve.org/CVERecord?id=CVE-2026-55153
Référence CVE CVE-2026-55276
https://www.cve.org/CVERecord?id=CVE-2026-55276
Référence CVE CVE-2026-55379
https://www.cve.org/CVERecord?id=CVE-2026-55379
Référence CVE CVE-2026-55380
https://www.cve.org/CVERecord?id=CVE-2026-55380
Référence CVE CVE-2026-55443
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0986Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-50162
Référence CVE CVE-2026-50163
https://www.cve.org/CVERecord?id=CVE-2026-50163
Référence CVE CVE-2026-50645
https://www.cve.org/CVERecord?id=CVE-2026-50645
Référence CVE CVE-2026-50734
https://www.cve.org/CVERecord?id=CVE-2026-50734
Référence CVE CVE-2026-53916
https://www.cve.org/CVERecord?id=CVE-2026-53916
Référence CVE CVE-2026-53917
https://www.cve.org/CVERecord?id=CVE-2026-53917
Référence CVE CVE-2026-54399
https://www.cve.org/CVERecord?id=CVE-2026-54399
Référence CVE CVE-2026-54428
https://www.cve.org/CVERecord?id=CVE-2026-54428
Référence CVE CVE-2026-54475
https://www.cve.org/CVERecord?id=CVE-2026-54475
Référence CVE CVE-2026-54512
https://www.cve.org/CVERecord?id=CVE-2026-54512
Référence CVE CVE-2026-54513
https://www.cve.org/CVERecord?id=CVE-2026-54513
Référence CVE CVE-2026-54514
https://www.cve.org/CVERecord?id=CVE-2026-54514
Référence CVE CVE-2026-54515
https://www.cve.org/CVERecord?id=CVE-2026-54515
Référence CVE CVE-2026-54516
https://www.cve.org/CVERecord?id=CVE-2026-54516
Référence CVE CVE-2026-54517
https://www.cve.org/CVERecord?id=CVE-2026-54517
Référence CVE CVE-2026-54518
https://www.cve.org/CVERecord?id=CVE-2026-54518
Référence CVE CVE-2026-5588
https://www.cve.org/CVERecord?id=CVE-2026-5588
Référence CVE CVE-2026-5598
https://www.cve.org/CVERecord?id=CVE
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0933Multiples vulnérabilités dans les produits IBMd?id=CVE-2026-54274
Référence CVE CVE-2026-54275
https://www.cve.org/CVERecord?id=CVE-2026-54275
Référence CVE CVE-2026-54276
https://www.cve.org/CVERecord?id=CVE-2026-54276
Référence CVE CVE-2026-54277
https://www.cve.org/CVERecord?id=CVE-2026-54277
Référence CVE CVE-2026-54278
https://www.cve.org/CVERecord?id=CVE-2026-54278
Référence CVE CVE-2026-54279
https://www.cve.org/CVERecord?id=CVE-2026-54279
Référence CVE CVE-2026-54280
https://www.cve.org/CVERecord?id=CVE-2026-54280
Référence CVE CVE-2026-54282
https://www.cve.org/CVERecord?id=CVE-2026-54282
Référence CVE CVE-2026-54283
https://www.cve.org/CVERecord?id=CVE-2026-54283
Référence CVE CVE-2026-54512
https://www.cve.org/CVERecord?id=CVE-2026-54512
Référence CVE CVE-2026-54513
https://www.cve.org/CVERecord?id=CVE-2026-54513
Référence CVE CVE-2026-54514
https://www.cve.org/CVERecord?id=CVE-2026-54514
Référence CVE CVE-2026-54515
https://www.cve.org/CVERecord?id=CVE-2026-54515
Référence CVE CVE-2026-54516
https://www.cve.org/CVERecord?id=CVE-2026-54516
Référence CVE CVE-2026-54517
https://www.cve.org/CVERecord?id=CVE-2026-54517
Référence CVE CVE-2026-54518
https://www.cve.org/CVERecord?id=CVE-2026-54518
Référence CVE CVE-2026-54530
https://www.cve.org/CVERecord?id=CVE-2026-54530
Référence CVE CVE-2026-54531
https://www.cve.org/CVERecord?id=
Official advisory ↗CERT-FR · French · CERTFR-2026-AVI-0914Multiples vulnérabilités dans Oracle Database Serverord?id=CVE-2026-46975
Référence CVE CVE-2026-47038
https://www.cve.org/CVERecord?id=CVE-2026-47038
Référence CVE CVE-2026-47039
https://www.cve.org/CVERecord?id=CVE-2026-47039
Référence CVE CVE-2026-47040
https://www.cve.org/CVERecord?id=CVE-2026-47040
Référence CVE CVE-2026-47045
https://www.cve.org/CVERecord?id=CVE-2026-47045
Référence CVE CVE-2026-47046
https://www.cve.org/CVERecord?id=CVE-2026-47046
Référence CVE CVE-2026-47060
https://www.cve.org/CVERecord?id=CVE-2026-47060
Référence CVE CVE-2026-47061
https://www.cve.org/CVERecord?id=CVE-2026-47061
Référence CVE CVE-2026-4738
https://www.cve.org/CVERecord?id=CVE-2026-4738
Référence CVE CVE-2026-54512
https://www.cve.org/CVERecord?id=CVE-2026-54512
Référence CVE CVE-2026-54513
https://www.cve.org/CVERecord?id=CVE-2026-54513
Référence CVE CVE-2026-54514
https://www.cve.org/CVERecord?id=CVE-2026-54514
Référence CVE CVE-2026-54515
https://www.cve.org/CVERecord?id=CVE-2026-54515
Référence CVE CVE-2026-54516
https://www.cve.org/CVERecord?id=CVE-2026-54516
Référence CVE CVE-2026-54517
https://www.cve.org/CVERecord?id=CVE-2026-54517
Référence CVE CVE-2026-54518
https://www.cve.org/CVERecord?id=CVE-2026-54518
Référence CVE CVE-2026-60175
https://www.cve.org/CVERecord?id=CVE-2026-60175
Référence CVE CVE-2026-61211
https://www.cve.org/CVERecord?id=
Official advisory ↗JVN iPedia · Japanese · JVNDB-2026-021137FasterXML, LLCのJackson-databindにおける複数の脆弱性jackson-databindはJackson Data Processorの汎用データバインディング機能およびツリーモデルを含んでいます。バージョン2.10.0から2.18.8、2.21.4、3.1.4までの間、jackson-databindのPolymorphicTypeValidator(PTV)は多態的なデシリアライズを保護する主要な安全機構です。多態的な型指定が有効で、型識別子にジェネリックパラメータが含まれる場合(つまり型ID文字列に「」が含まれる場合)、DatabindContext._resolveAndValidateGeneric()は設定されたPTVに対して生のコンテナクラス名(「」以前の部分文字列)のみを検証します。コンテナ型が承認されると、このメソッドはTypeFactory.constructFromCanonical()を使用して完全なカノニカル型文字列を解析し、ネストされた型引数をPTVで検証することなく完全にパラメータ化された型を返します。ネストされた型引数はその後デシリアライズ中に解決およびインスタンス化され、Beanとしてプロパティが設定されます。攻撃者が型IDを制御できる場合、許可されたコンテナのジェネリック型パラメータとして拒否されたクラスを配置することが可能です。例えば、java.util.ArrayListcom.evil.Gadgetはjava.util.ArrayListのみが許可リストにある場合でも、コンテナはPTVチェックを通過します。com.evil.GadgetはClass.forName(name, true, loader)でロードされてインスタンス化され、そのプロパティは攻撃者が制御するJSONから設定されます。これにより、明示的に構成されたPTV許可リストが完全に回避されます。この脆弱性はバージョン2.18.8、2.21.4および3.1.4で修正されました。
Official advisory ↗NCSC-NL · Dutch · NCSC-2026-0325Kwetsbaarheden verholpen in Atlassian productenMultiple vulnerabilities in jackson-databind, including a PolymorphicTypeValidator bypass via nested generic type parameters, along with issues in Keycloak SAML assertion validation and Oracle Utilities Application Framework denial of service, have been addressed in recent updates.
Official advisory ↗