Atlassian and NCSC-NL said on August 24 that security updates now cover 83 CVEs across Bamboo, Bitbucket, Confluence, Jira, Crowd, and Fisheye. The fixes span multiple Server and Data Center products, not a single bug in one app.
The vulnerable code is often in third-party libraries Atlassian ships inside those products, so the vendor had to fold upstream patches into its own releases. That means the risk is shared across products that reuse the same dependencies, and the fix lives in the Atlassian release for each product rather than in the library on its own.
For teams running several self-hosted Atlassian apps side by side, the exposure map is a stack of separate version lines, not one uniform patch event. A missed product can leave reused code paths live even after neighboring services are updated.