Atlassian and Splunk Push Patches for More Than 250 Flaws, Including Critical Bugs
Two major software vendors dropped sweeping security updates this week. Here is what changed, what could go wrong without the fix, and what ordinary users should know.

Key points
- Atlassian patched 10 critical and 162 high-severity vulnerabilities across six products on Tuesday, covering roughly 109 unique CVEs.
- Splunk announced fixes for at least 150 vulnerabilities across Splunk Enterprise, SOAR, Universal Forwarder, and related apps on Wednesday.
- Splunk Enterprise versions 10.4.2, 10.2.6, 10.0.9, and 9.4.14 include fixes for 60 flaws, three of them rated critical.
- Successful exploitation of the Atlassian bugs could let attackers run any code they choose on a victim's server, steal data, or impersonate legitimate users.
- Both companies say updated software is already available; organisations running older versions should treat patching as urgent.
What happened?
Back-to-back patch releases from two of the software world's bigger names landed this week. Atlassian, the company behind Jira and Confluence (tools that millions of teams use to manage projects and documents), published its bulletin on Tuesday. Splunk, whose software is widely used to monitor and search through IT logs, followed on Wednesday.
Neither company discovered a single dramatic flaw. Instead, both found that third-party code libraries, meaning chunks of ready-made software built by others and bundled inside their products, contained a long list of known weaknesses. When those libraries go unpatched, every product that includes them becomes vulnerable by extension.
What could attackers actually do?
A lot. The Atlassian flaws, if left unpatched, could let an attacker run arbitrary code remotely, which means they could execute their own commands on a company's server from anywhere on the internet without needing physical access. Other risks included authentication bypass, where someone logs in without a valid password, and man-in-the-middle attacks, where a criminal secretly intercepts traffic passing between a user and a server.
Splunk's critical bugs sit inside Splunk Enterprise and several of its apps, including the AI Toolkit, Connect for Kafka, and its On-Call service. Splunk SOAR, which is software companies use to automate their security responses, also received critical fixes.
Would multi-factor authentication (MFA), the system where a login requires a second proof of identity such as a text message code, have stopped these? Honestly, only partly. Authentication-bypass flaws are specifically designed to sidestep login controls, so MFA alone is not a substitute for patching.
Who is affected and what are the fixed versions?
| Product | Fixed version(s) | Severity highlights |
|---|---|---|
| Atlassian Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, Jira | See Atlassian's bulletin | 10 critical, 162 high |
| Splunk Enterprise | 10.4.2, 10.2.6, 10.0.9, 9.4.14 | 3 critical among 60 fixed |
| Splunk Enterprise Security | 8.6.1 | 2 high-severity |
| Splunk Universal Forwarder | Latest release | 3 medium (OpenSSL) |
| Splunk SOAR | Latest release | Multiple critical (third-party) |
Should ordinary users worry?
Most people do not run these products themselves. These are tools used by IT teams inside companies, hospitals, banks, and government offices. The concern for ordinary people is indirect: if an organisation that holds your data runs an unpatched version of these products and gets breached, your records could be exposed.
If you work in IT or security, the action is simple. Check your installed versions against the table above, consult Atlassian's full security bulletin and Splunk's advisory, and update without delay. First reported by SecurityWeek, the combined scope of both releases makes this one of the larger patch weeks of the year.
There is no evidence, as of publication, that any of these flaws are being actively exploited in the wild. That gap between patch release and exploitation is exactly the window that matters.



