Atlassian and Splunk Push Patches for More Than 250 Flaws, Including Critical Bugs
Two major software vendors dropped sweeping security updates this week. Here is what changed, what could go wrong without the fix, and what ordinary users should know.

Key points
- Atlassian patched 10 critical and 162 high-severity vulnerabilities across six products on Tuesday, covering roughly 109 unique CVEs.
- Splunk announced fixes for at least 150 vulnerabilities across Splunk Enterprise, SOAR and Universal Forwarder on Wednesday.
- Splunk Enterprise versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14 include fixes for 60 flaws, three of them rated critical.
- Successful exploitation of the Atlassian bugs could let attackers run arbitrary code remotely, steal data or bypass authentication entirely.
- Both companies say updated software is already available; organisations running older versions should treat patching as urgent.
What happened?
Back-to-back patch releases from two of enterprise software's bigger names landed this week. Atlassian, the company behind Jira and Confluence, published its bulletin on Tuesday. Splunk, whose software monitors and searches IT logs, followed on Wednesday.
Neither company discovered a single dramatic flaw. Both found that third-party code libraries bundled inside their products carried a long list of known weaknesses. When those libraries go unpatched, every product that includes them becomes vulnerable by extension. Atlassian's Confluence and Jira have been on our radar since August: our story on a single-click data-theft flaw in Rovo showed how quickly things can go wrong when these platforms aren't kept tight.
What could attackers actually do?
A lot. Atlassian's unpatched flaws could let an attacker run arbitrary code remotely, meaning their own commands on a company's server from anywhere on the internet, with no physical access needed. Other risks include authentication bypass, where someone logs in without valid credentials, server-side request forgery, denial of service, and man-in-the-middle attacks that silently intercept traffic between a user and a server.
Splunk's critical bugs sit inside Splunk Enterprise and several apps, including the AI Toolkit, the Connect for Kafka add-on, and SOAR (software companies use to automate security responses). MFA, the login step that demands a second proof of identity, won't save you from authentication-bypass flaws. They're built to get around login controls. Patching is the only fix.
Who is affected and what are the fixed versions?
| Product | Fixed version(s) | Severity highlights |
|---|---|---|
| Atlassian Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, Jira | See Atlassian's bulletin | 10 critical, 162 high |
| Splunk Enterprise | 10.4.2, 10.2.6, 10.0.9, 9.4.14 | 3 critical among 60 fixed |
| Splunk Enterprise Security | 8.6.1 | 2 high-severity |
| Splunk Universal Forwarder | Latest release | 3 medium (OpenSSL) |
| Splunk SOAR | Latest release | Multiple critical (third-party) |
Should ordinary users worry?
Most people don't run these products themselves. They're tools used by IT teams inside companies, hospitals and government offices. The risk for everyone else is indirect: if an organisation holding your data runs an unpatched version and gets breached, your records could be exposed.
If you work in IT or security, check your installed versions against the table above, consult Atlassian's full security bulletin and Splunk's advisory, and update without delay. First reported by SecurityWeek, the combined scope makes this one of the larger patch weeks of the year.
There's no evidence, as of publication, that any of these flaws are being actively exploited. That gap between patch release and exploitation is the window that matters. It closes faster than most teams expect.



