Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To verify an Atlassian Data Center security patch, find the exact security advisory for the vulnerability, identify the fixed-version entry for your product and release branch, then compare it with the version reported by the running instance. Atlassian documents this version comparison as its check for whether an instance was successfully updated. It is useful evidence, but it does not by itself prove every cluster node completed rollout or that a potentially compromised host is clean.

Use the advisory for the exact vulnerability

Start with the specific CVE or security bulletin item—not a general claim that the system is “patched” or “up to date.” Atlassian’s Security Advisories portal indexes security advisories and monthly bulletins. Open the advisory that matches the vulnerability you addressed, then check its fixed-version guidance.

Atlassian’s FAQ for CVE-2022-26136 and CVE-2022-26137 states that you can verify an update by comparing an instance’s version number with the fixed versions listed in the security advisory. Treat that as the method, not as a source of thresholds for other vulnerabilities: each advisory can have different requirements.

Compare the running version with the correct fixed-version entry

  1. Identify the affected product. Confirm whether the advisory applies to Jira, Confluence, Bitbucket, Bamboo, Crowd, or another Atlassian Data Center product.
  2. Match the release branch. In the advisory’s fixed-version table, find the row for that exact product and branch. Do not use another product’s threshold or assume version numbers are interchangeable.
  3. Check the running instance’s reported version. Compare that value with the fixed version for the matching row. Atlassian’s FAQ describes this comparison as verification that the instance was successfully updated.
  4. Check the guidance’s date and linked release notes. Fixed-version tables are time-bounded. Atlassian’s July 15, 2025 security bulletin says its fixed-version table is current as of publication and directs readers to linked release notes for the most up-to-date versions. For an actual patch decision, consult the current advisory and its linked release notes rather than relying on an old threshold.

For example, the advisory for CVE-2022-26136 and CVE-2022-26137 lists different fixed-version thresholds across products. Those historical values are not current patch guidance and must not be transferred to a different CVE or product.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check support status before treating a version as a safe destination

A version comparison answers whether the reported version meets the advisory’s listed fixed-version threshold. Also check whether the release is supported and whether a later advisory or linked release notes recommend a newer release. Atlassian’s Data Center bug-fix policy describes which currently supported releases receive critical fixes; unsupported feature versions may need an upgrade to a supported or LTS release.

If your current branch is absent from the advisory, or you cannot determine whether its version is covered, do not infer that it is fixed. Consult the current advisory, its release notes, and Atlassian’s Data Center bug-fix policy before deciding what to deploy.

Record the check and confirm rollout separately

Keep a record that lets another administrator reproduce the verification. Atlassian’s Data Center security checklist advises documenting security measures and monitoring that they remain in place, including after an upgrade or migration.

  • The advisory or CVE checked
  • The affected product and release branch
  • The version reported by the running instance
  • The fixed-version row consulted and the date checked
  • The deployment or change record associated with the update

For a clustered deployment, use your organization’s deployment controls to confirm that the rollout completed across the environment. A version reported by an instance is not, on its own, proof that every node has completed the rollout; the cited Atlassian verification guidance does not provide a complete node-by-node validation procedure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use Instance Health as supplementary visibility

For Jira and Confluence Data Center, Atlassian’s Security Hub describes Instance Health as a way to see CVE exposure and security misconfigurations. Atlassian also describes a manual support.zip upload option for environments that cannot connect to the cloud. This can add visibility, but it does not replace checking the fixed-version requirement in the exact advisory.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Know what version verification cannot establish

A matching reported version establishes that the version comparison Atlassian documents matches the advisory’s fixed-version entry. It is not a forensic clean bill of health if an attacker may have accessed the system. If compromise is possible, follow your organization’s incident-response process and preserve relevant evidence; patch verification and incident investigation are different tasks.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.