endoflife.ai
EOL Checker Products EOL Watch Get Support

Atlassian's Two-Year Treadmill: Every Jira and Confluence Data Center Version Dies Two Years After Its Own Release — and the Server Ghost Fleet Keeps Getting Ransomed

Published: August 11, 2026  ·  EOL Watch — lifecycle coverage  ·  Dates verified against Atlassian's end-of-life policy, Atlassian's Server end-of-support announcement, the CISA KEV catalog (2026-08-10 release), and our tracked lifecycle data — methodology

There is no evergreen Atlassian self-hosted version. Atlassian's end-of-life policy is one sentence long where it matters: Atlassian "supports releases for two years after the initial feature or Long-Term Support (LTS) release." Every Jira Software Data Center and Confluence Data Center version starts its own two-year clock the day it ships, and when the clock runs out — security fixes included — that version is done, no matter how many versions came after it or how "recent" it feels.

The clock runs faster than most upgrade cadences. As of today, the oldest supported Jira Data Center release is Jira 10.0, released August 22, 2024 — and it reaches end of life on August 22, 2026, eleven days from now. On the Confluence side the line has already moved: Confluence 9.0, released July 30, 2024, reached end of life on July 30, 2026. If you are on it, you are not "one major version behind" — you are unsupported, and the next fix Atlassian ships will not apply to you.

And behind the Data Center treadmill sits a darker lifecycle story. Atlassian Server — the perpetual-license product an unknown but large number of organizations never migrated off — lost all support and bug fixes on February 15, 2024. That fleet has now run two and a half years without a single patch, while Confluence Server versions rank among the most ransomware-targeted software in CISA's entire Known Exploited Vulnerabilities catalog: three separate Confluence CVEs with confirmed ransomware campaign use, each permanently unpatchable on the end-of-life versions attackers find them on. Our Exploited & Unpatchable feed documents all three, with exact affected and fixed versions.

The state of Atlassian self-hosted, August 11, 2026: Jira Software Data Center — 10.0 through 11.3 supported; 10.0 dies August 22, 2026; current LTS is 11.3 (to December 3, 2027). Confluence Data Center — 9.1 through 10.2 supported; 9.0 already EOL (July 30, 2026); 9.1 dies October 3, 2026; current LTS is 10.2 (to December 2, 2027). Server (all products) — end of support February 15, 2024; no patches at any severity since. Full tables below.

The policy: two years, from that version's release — not from the product's

Atlassian's support model is unusually easy to state and unusually easy to misread. The policy's own worked example: "We support Jira Software Data Center 10.4.0 for two years, until January 22, 2027, because we shipped it on January 22, 2025." That matches our tracked data exactly — and it means the support window is a property of the version you installed, not of the product line. Jira Data Center is fully supported as a product; the Jira 10.1 instance you deployed in October 2024 still dies this October.

Two consequences follow. First, the practical window is shorter than two years: nobody installs a release on its ship date, so an organization that adopts a version six months after release has eighteen months before it must move again. Second, "we upgraded recently" and "we are supported" are different claims — a team that jumped to Jira 10.4 in early 2025 did the right thing and still faces a January 22, 2027 deadline.

The pressure valve is the Long-Term Support (Enterprise) release. Roughly once a year, Atlassian designates one feature release as LTS and keeps shipping bug-fix updates on that line for its full two-year window — per our data, the recent LTS lines are Jira 9.12, 10.3 and 11.3, and Confluence 8.5, 9.2 and 10.2, and the long-running fix streams are real (Jira 10.3 is at 10.3.24; Confluence 9.2 at 9.2.23). An LTS release gets the same two years as any other release — what it buys you is a stable platform to sit on between upgrades, not extra time. Organizations that hop LTS-to-LTS upgrade about once a year and spend most of that time on a maintained line; organizations that adopt non-LTS feature releases carry the same two-year deadline with fewer backported fixes.

Running Confluence past end of life?
Extended support past the official EOL date exists for many products in this position — whether it covers Confluence is exactly what we check. Tell us where to reach you and we’ll reply with matched options and pricing guidance — or an honest “no vendor covers this.” Free, no obligation.

Free · No obligation · Independent — we track the dates, vendors don’t pay for placement · dates verified against vendor sources. See all support options →

Jira Software Data Center: every version's dates

All currently supported Jira Software Data Center releases plus the two most recently expired, from our tracked Jira Software data. Every version links to its lifecycle page with live status and risk score.

VersionStatusReleasedSupport ends (EOL)Notes
Jira 11.3SupportedDec 3, 2025Dec 3, 2027Current LTS (Enterprise release); latest fix 11.3.10
Jira 11.2SupportedNov 6, 2025Nov 6, 2027Feature release
Jira 11.1SupportedSep 24, 2025Sep 24, 2027Feature release
Jira 11.0SupportedAug 13, 2025Aug 13, 2027First 11.x platform release
Jira 10.7SupportedJun 13, 2025Jun 13, 2027Feature release
Jira 10.6SupportedApr 23, 2025Apr 23, 2027Feature release
Jira 10.5SupportedMar 12, 2025Mar 12, 2027Feature release
Jira 10.4WarningJan 22, 2025Jan 22, 2027The policy's own worked example — two years to the day
Jira 10.3WarningDec 5, 2024Dec 5, 2026LTS; latest fix 10.3.24 — under four months left
Jira 10.2WarningNov 20, 2024Nov 20, 2026Feature release
Jira 10.1WarningOct 9, 2024Oct 9, 2026Feature release
Jira 10.0WarningAug 22, 2024Aug 22, 2026Oldest supported release — dies in 11 days
Jira 9.17EOLJun 26, 2024Jun 26, 2026Last 9.x feature release; expired June 2026
Jira 9.12EOLNov 29, 2023Nov 29, 2025Former LTS; fix stream reached 9.12.38

Confluence Data Center: every version's dates

All currently supported Confluence Data Center releases plus the three most recently expired, from our tracked Confluence data. Note the top of the dead list: 9.0 is not old — it expired twelve days ago.

VersionStatusReleasedSupport ends (EOL)Notes
Confluence 10.2SupportedDec 2, 2025Dec 2, 2027Current LTS (Enterprise release); latest fix 10.2.15
Confluence 10.1SupportedOct 7, 2025Oct 7, 2027Feature release
Confluence 10.0SupportedAug 5, 2025Aug 5, 2027First 10.x platform release
Confluence 9.5SupportedJun 4, 2025Jun 4, 2027Feature release
Confluence 9.4SupportedMar 31, 2025Apr 1, 2027Feature release
Confluence 9.3WarningFeb 4, 2025Feb 4, 2027Feature release — inside six months
Confluence 9.2WarningDec 9, 2024Dec 10, 2026LTS; latest fix 9.2.23 — four months left
Confluence 9.1WarningOct 3, 2024Oct 3, 2026Oldest supported release — dies October 3
Confluence 9.0EOLJul 30, 2024Jul 30, 2026Expired July 30, 2026 — twelve days ago
Confluence 8.9EOLApr 1, 2024Apr 2, 2026Last 8.x feature release
Confluence 8.5EOLAug 21, 2023Dec 15, 2025Former LTS; fix stream reached 8.5.31

Dates from our tracked dataset (verification pass 2026-08-11), cross-checked against Atlassian's end-of-life policy. Atlassian occasionally extends an LTS line slightly past two calendar years (Confluence 8.5 ran to December 15, 2025); we list the tracked dates. Badges and dates in these tables are re-verified against the data layer at every site build.

The Server ghost fleet: zero patches since February 15, 2024

Data Center is the treadmill; Server is the graveyard. Atlassian stopped selling new Server licenses on February 2, 2021, and on February 15, 2024 the line in its migration announcement came due: "support and bug fixes will no longer be available for your server products." Not "reduced support" — none, at any severity, for any Server product, forever.

That would be a routine end-of-life story if Server installs had actually disappeared. The exploitation record says they did not. Confluence Server's flaws keep being exploited years after disclosure — which only happens when unpatched instances remain reachable in numbers worth an attacker's time. Three Confluence entries in CISA's Known Exploited Vulnerabilities catalog — re-confirmed against the live catalog (2026-08-10 release) before publishing — carry the KEV field that matters most: known ransomware campaign use. And each one affects version lines that were already end of life when the fixes shipped, meaning the versions the ghost fleet actually runs never got, and never will get, a patch:

CVEFlawKEV listedRansomware usePermanently unpatched on
CVE-2021-26084Unauthenticated OGNL injection → remote code execution (CVSS 9.8)Nov 3, 2021KnownConfluence 6.0–6.12 (and older 4.x/5.x); fixes shipped only on 6.13, 7.4, 7.11, 7.12, 7.13
CVE-2022-26134Unauthenticated OGNL injection → remote code execution (CVSS 9.8)Jun 2, 2022KnownConfluence 6.x — Atlassian's advisory names every release after 1.3.0 as affected; fixes shipped only on 7.4 and 7.13–7.18
CVE-2023-22518Improper authorization → unauthenticated instance reset and admin-account creation (CVSS 9.8; Atlassian revised to 10.0)Nov 7, 2023KnownConfluence 5.x, 6.x, and every non-LTS 7.0–7.18 line; fixes shipped only on 7.19.16, 8.3.4, 8.4.4, 8.5.3, 8.6.1

Read that pattern once more, because it is the whole argument: three times in three consecutive years, a critical unauthenticated Confluence flaw was disclosed, mass-exploited, adopted by ransomware operators, and fixed only on the version lines still inside their two-year windows. Every line outside the window got silence. CVE-2023-22518 is the starkest case — an attacker needs no credentials to wipe a Confluence instance and create their own administrator account, ransomware groups picked it up within days of disclosure in November 2023, and on the 5.x, 6.x and non-LTS 7.x lines there is no patch to apply and never will be.

All three entries — with CVSS vectors, affected-version statements from Atlassian's own advisories, fixed-version lists, and the reasoning for why each qualifies as permanently unpatchable — are maintained in our Exploited & Unpatchable feed, the curated intersection of CISA's KEV catalog with end-of-life version data. It is also available as a free JSON feed. Confluence is one of the feed's most represented products — a distinction no vendor wants.

The operational takeaway for anyone who inherited an Atlassian estate: finding a Server instance is finding an incident waiting to be scheduled. The versions in the table above are exactly the versions a forgotten 2019-era Confluence Server runs. Scan for it the way the attackers do — it answers on the network, and every one of these CVEs has public, weaponized exploit code.

The decision fork: the treadmill, or the Cloud

Atlassian's self-hosted lifecycle now offers exactly two honest paths, and pretending there is a third — staying put — is how organizations end up in the table above.

Path 1 — run the Data Center treadmill deliberately. Accept the two-year cadence and plan around the LTS (Enterprise) releases: land on the current LTS — Jira 11.3 and Confluence 10.2, both supported to early December 2027 — and schedule the next hop before each window closes. This is a real, supported strategy; it simply has a recurring cost that perpetual-license Server never had, roughly one upgrade project per product per year to eighteen months. One caveat belongs in the plan: per our Atlassian Data Center tracker, Atlassian has closed Data Center to new customers (March 30, 2026), ends existing-customer renewals March 30, 2028, and has announced full Data Center end of life on March 28, 2029 — so the treadmill itself now has a published finish line, and a Data Center commitment made today is a bridge measured in single-digit years.

Path 2 — move to Atlassian Cloud. This is the destination Atlassian's own lifecycle decisions point toward, and it removes the version clock entirely — there is no version to be on. The trade-offs are the standard self-hosted-to-SaaS ones (data residency, compliance regimes, plugin/app parity, and pricing that scales differently than a perpetual license did), and they are real evaluation work rather than a footnote. What the Cloud path is not is optional to evaluate: with Server dead since 2024 and Data Center's own end of life announced, every Atlassian self-hosted roadmap now needs a written answer to "Cloud when, or off Atlassian to what?"

What is not a path is the status quo. The Server exploitation record above is what "we'll decide later" looks like three years on — and the Data Center two-year clock means "later" arrives on a schedule you can read off the tables in this article.

We track every Jira Software release, every Confluence release, the Atlassian Data Center platform dates, and 480+ other products against vendor-verified datescheck any version in seconds, or see what else hits end of life this quarter.

What to do about it

Confluence currently carries an EOL Risk Score™ of 35/100 — Grade B, moderate risk, recalculated at every site build from EOL recency, attack surface, CISA KEV exposure, and extended-support availability. Per-version scores and dates are on the Confluence lifecycle page.

The right response comes down to one question: how many more years does this system need to run? Under a year, extended support (where it exists) is usually cheaper than an emergency migration. One to three years, migrate — support fees paid repeatedly cost more than doing the project once. Indefinitely, migrate now and plan the next one before it surprises you. Extended support is often the more expensive choice over a multi-year horizon — a bridge, not a destination.

Frequently Asked Questions

How long does Atlassian support each Jira and Confluence Data Center version?

Two years, measured from that version's own release date. Atlassian's end-of-life policy states that it "supports releases for two years after the initial feature or Long-Term Support (LTS) release" — its own worked example: Jira Software Data Center 10.4.0 is supported until January 22, 2027 because it shipped January 22, 2025. So Jira Data Center 11.3 (released December 3, 2025) is supported until December 3, 2027, and Confluence 9.5 (released June 4, 2025) until June 4, 2027. There is no evergreen version: every release, LTS included, carries its own two-year clock.

Is Atlassian Server (Jira Server, Confluence Server) still supported?

No. Atlassian ended support for all Server products on February 15, 2024 — its announcement states that "support and bug fixes will no longer be available for your server products." New Server license sales had already stopped on February 2, 2021. Any organization still running Jira Server or Confluence Server in August 2026 has gone roughly two and a half years without a single security patch, and no future patch will ever come.

Which Jira and Confluence Data Center versions are still supported right now?

As of August 11, 2026, per our tracked data: Jira Software Data Center 10.0 through 11.3 are inside their two-year windows — but the oldest, Jira 10.0, reaches end of life on August 22, 2026. For Confluence Data Center, 9.1 through 10.2 are supported; Confluence 9.0 already reached end of life on July 30, 2026, and Confluence 9.1's window closes October 3, 2026. The current LTS releases are Jira 11.3 (supported to December 3, 2027) and Confluence 10.2 (supported to December 2, 2027).

Are old Confluence versions really still being exploited?

Yes — Confluence Server is among the most ransomware-targeted software in CISA's Known Exploited Vulnerabilities catalog. Three separate Confluence CVEs — CVE-2021-26084, CVE-2022-26134, and CVE-2023-22518 — are KEV-listed with known ransomware campaign use, and each affects version lines that were already end of life when the fixes shipped, so those versions will never receive a patch. All three are documented, with exact affected and fixed versions, in our Exploited & Unpatchable feed.

Related

The Monthly EOL Digest™

Once a month — critical EOL dates, CVE blind spots, and lifecycle changes worth knowing.

© 2026 endoflife.ai · How we verify our dates · API · About · Data from endoflife.date (MIT)