The current version of Confluence Data Center is 10.2.19 (as of 05/10/2026). patchletter checks the official source daily and emails you new releases.
Actively exploited vulnerabilities
The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. What CISA does not carry does not appear in this list — even where it is being exploited.
- CVE-2021-26084Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection VulnerabilityRansomware
9.8 critical · over the network, without login · CISA deadline was 17 Nov 21
- CVE-2022-26134Atlassian Confluence Server and Data Center Remote Code Execution VulnerabilityRansomware
9.8 critical · over the network, without login · CISA deadline was 6 Jun 22
- CVE-2023-22515Atlassian Confluence Data Center and Server Broken Access Control VulnerabilityRansomware
9.8 critical · over the network, without login · CISA deadline was 13 Oct 23
- CVE-2023-22518Atlassian Confluence Data Center and Server Improper Authorization VulnerabilityRansomware
9.8 critical · over the network, without login · CISA deadline was 28 Nov 23
- CVE-2023-22527Atlassian Confluence Data Center and Server Template Injection VulnerabilityRansomware
9.8 critical · over the network, without login · CISA deadline was 14 Feb 24
- CVE-2019-3398Atlassian Confluence Server and Data Center Path Traversal Vulnerability
8.8 high · over the network, with a basic account · CISA deadline was 3 May 22
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
BSI security advisories
Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.
- Atlassian Bamboo, Bitbucket, Confluence, Fisheye/Crucible, Jira Software und Jira Service Management: Mehrere Schwachstellen
WID-SEC-W-2026-3376 · 9 Oct
- Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye und Jira): Schwachstelle ermöglicht Offenlegung von Informationen
WID-SEC-W-2026-3755 · 8 Oct
- Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, und Jira): Mehrere Schwachstellen
WID-SEC-W-2026-2923 · 5 Oct
- Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere Schwachstellen
WID-SEC-W-2026-2460 · 2 Oct
- Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere Schwachstellen
WID-SEC-W-2026-1955 · 24 Sept
- Apache Tomcat: Mehrere Schwachstellen
WID-SEC-W-2025-0895 · 18 Sept
- Apache Tomcat: Mehrere Schwachstellen
WID-SEC-W-2024-3722 · 18 Sept
- Apache Tomcat: Schwachstelle ermöglicht Codeausführung
WID-SEC-W-2024-3744 · 18 Sept
Confluence Data Center at a glance
Confluence is Atlassian's widely used team wiki and collaboration platform, common for internal documentation. Atlassian ships regular releases of the self-managed Data Center product plus frequent security advisories; as a system holding sensitive internal knowledge and often internet-facing, prompt patching is essential.
For admins the security advisories are the rhythm: Confluence has been the target of serious, actively exploited vulnerabilities, so apply security releases immediately, especially on any internet-facing instance. Updates run database migrations — back up the database and home directory first, and follow the documented upgrade path, minding app (plugin) compatibility. Keep Confluence behind SSO with strong authentication and, ideally, off the open internet. Apps carry their own updates and risk. After upgrading, verify login, spaces and apps. Track the version and its support window, and subscribe to Atlassian security advisories; patchletter surfaces new Confluence releases.
Support cycles (endoflife.date)
| Cycle | Latest version | Status |
|---|---|---|
| 10.2LTS | 10.2.19 | EOL 2 Dec 27 |
| 10.1 | 10.1.2 | EOL 7 Oct 27 |
| 10.0 | 10.0.3 | EOL 5 Aug 27 |
| 9.5 | 9.5.4 | EOL 4 Jun 27 |
| 9.4 | 9.4.1 | EOL 1 Apr 27 |
| 9.3 | 9.3.2 | EOL 4 Feb 27 |
| 9.2LTS | 9.2.26 | EOL in 60 days |
| 9.1 | 9.1.1 | End of Life |
Version history & changelog · as detected by patchletter
| Version | Channel | Date | Notes |
|---|---|---|---|
| 10.2.19 | LTS | 05/10/2026 | – |
| 10.2.18 | LTS | 08/09/2026 | – |
| 10.2.17 | LTS | 06/09/2026 | – |
| 10.2.16 | LTS | 01/09/2026 | – |
| 10.2.15 | LTS | 04/08/2026 | – |
| 10.2.14 | LTS | 09/07/2026 | – |
| 10.2.13 | LTS | 02/06/2026 | – |
Frequently asked questions
- What is the latest version of Confluence Data Center?
- Confluence Data Center 10.2.19, released 05/10/2026. patchletter checks the vendor's official source daily for new releases.
- Where can I find the Confluence Data Center release notes?
- The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
- How do I get notified about new Confluence Data Center updates?
- Tick Confluence Data Center off in the catalogue and leave your address. From then on new versions go out by email — one at a time, or bundled in the daily or weekly digest.
An email as soon as a new Confluence Data Center version ships
We reconcile the vendor source daily. When a new version appears, it lands in your inbox right away or bundled as a digest. The update email is free and ends with one click. Alerts about vulnerabilities and end of support are part of patchletter Pro.
Embed this badge
The badge shows the current Confluence Data Center version and keeps it up to date. Anyone may embed it, no account needed.
[](https://patchletter.com/en/software/confluence)https://patchletter.com/badge/confluence.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).