Atlassian's Two-Year Treadmill: Every Jira and Confluence Data Center Version Dies Two Years After Its Own Release — and the Server Ghost Fleet Keeps Getting Ransomed
There is no evergreen Atlassian self-hosted version. Atlassian's end-of-life policy is one sentence long where it matters: Atlassian "supports releases for two years after the initial feature or Long-Term Support (LTS) release." Every Jira Software Data Center and Confluence Data Center version starts its own two-year clock the day it ships, and when the clock runs out — security fixes included — that version is done, no matter how many versions came after it or how "recent" it feels.
The clock runs faster than most upgrade cadences. As of today, the oldest supported Jira Data Center release is Jira 10.0, released August 22, 2024 — and it reaches end of life on August 22, 2026, eleven days from now. On the Confluence side the line has already moved: Confluence 9.0, released July 30, 2024, reached end of life on July 30, 2026. If you are on it, you are not "one major version behind" — you are unsupported, and the next fix Atlassian ships will not apply to you.
And behind the Data Center treadmill sits a darker lifecycle story. Atlassian Server — the perpetual-license product an unknown but large number of organizations never migrated off — lost all support and bug fixes on February 15, 2024. That fleet has now run two and a half years without a single patch, while Confluence Server versions rank among the most ransomware-targeted software in CISA's entire Known Exploited Vulnerabilities catalog: three separate Confluence CVEs with confirmed ransomware campaign use, each permanently unpatchable on the end-of-life versions attackers find them on. Our Exploited & Unpatchable feed documents all three, with exact affected and fixed versions.
The policy: two years, from that version's release — not from the product's
Atlassian's support model is unusually easy to state and unusually easy to misread. The policy's own worked example: "We support Jira Software Data Center 10.4.0 for two years, until January 22, 2027, because we shipped it on January 22, 2025." That matches our tracked data exactly — and it means the support window is a property of the version you installed, not of the product line. Jira Data Center is fully supported as a product; the Jira 10.1 instance you deployed in October 2024 still dies this October.
Two consequences follow. First, the practical window is shorter than two years: nobody installs a release on its ship date, so an organization that adopts a version six months after release has eighteen months before it must move again. Second, "we upgraded recently" and "we are supported" are different claims — a team that jumped to Jira 10.4 in early 2025 did the right thing and still faces a January 22, 2027 deadline.
The pressure valve is the Long-Term Support (Enterprise) release. Roughly once a year, Atlassian designates one feature release as LTS and keeps shipping bug-fix updates on that line for its full two-year window — per our data, the recent LTS lines are Jira 9.12, 10.3 and 11.3, and Confluence 8.5, 9.2 and 10.2, and the long-running fix streams are real (Jira 10.3 is at 10.3.24; Confluence 9.2 at 9.2.23). An LTS release gets the same two years as any other release — what it buys you is a stable platform to sit on between upgrades, not extra time. Organizations that hop LTS-to-LTS upgrade about once a year and spend most of that time on a maintained line; organizations that adopt non-LTS feature releases carry the same two-year deadline with fewer backported fixes.
Jira Software Data Center: every version's dates
All currently supported Jira Software Data Center releases plus the two most recently expired, from our tracked Jira Software data. Every version links to its lifecycle page with live status and risk score.
| Version | Status | Released | Support ends (EOL) | Notes |
|---|---|---|---|---|
| Jira 11.3 | Supported | Dec 3, 2025 | Dec 3, 2027 | Current LTS (Enterprise release); latest fix 11.3.10 |
| Jira 11.2 | Supported | Nov 6, 2025 | Nov 6, 2027 | Feature release |
| Jira 11.1 | Supported | Sep 24, 2025 | Sep 24, 2027 | Feature release |
| Jira 11.0 | Supported | Aug 13, 2025 | Aug 13, 2027 | First 11.x platform release |
| Jira 10.7 | Supported | Jun 13, 2025 | Jun 13, 2027 | Feature release |
| Jira 10.6 | Supported | Apr 23, 2025 | Apr 23, 2027 | Feature release |
| Jira 10.5 | Supported | Mar 12, 2025 | Mar 12, 2027 | Feature release |
| Jira 10.4 | Warning | Jan 22, 2025 | Jan 22, 2027 | The policy's own worked example — two years to the day |
| Jira 10.3 | Warning | Dec 5, 2024 | Dec 5, 2026 | LTS; latest fix 10.3.24 — under four months left |
| Jira 10.2 | Warning | Nov 20, 2024 | Nov 20, 2026 | Feature release |
| Jira 10.1 | Warning | Oct 9, 2024 | Oct 9, 2026 | Feature release |
| Jira 10.0 | Warning | Aug 22, 2024 | Aug 22, 2026 | Oldest supported release — dies in 11 days |
| Jira 9.17 | EOL | Jun 26, 2024 | Jun 26, 2026 | Last 9.x feature release; expired June 2026 |
| Jira 9.12 | EOL | Nov 29, 2023 | Nov 29, 2025 | Former LTS; fix stream reached 9.12.38 |
Confluence Data Center: every version's dates
All currently supported Confluence Data Center releases plus the three most recently expired, from our tracked Confluence data. Note the top of the dead list: 9.0 is not old — it expired twelve days ago.
| Version | Status | Released | Support ends (EOL) | Notes |
|---|---|---|---|---|
| Confluence 10.2 | Supported | Dec 2, 2025 | Dec 2, 2027 | Current LTS (Enterprise release); latest fix 10.2.15 |
| Confluence 10.1 | Supported | Oct 7, 2025 | Oct 7, 2027 | Feature release |
| Confluence 10.0 | Supported | Aug 5, 2025 | Aug 5, 2027 | First 10.x platform release |
| Confluence 9.5 | Supported | Jun 4, 2025 | Jun 4, 2027 | Feature release |
| Confluence 9.4 | Supported | Mar 31, 2025 | Apr 1, 2027 | Feature release |
| Confluence 9.3 | Warning | Feb 4, 2025 | Feb 4, 2027 | Feature release — inside six months |
| Confluence 9.2 | Warning | Dec 9, 2024 | Dec 10, 2026 | LTS; latest fix 9.2.23 — four months left |
| Confluence 9.1 | Warning | Oct 3, 2024 | Oct 3, 2026 | Oldest supported release — dies October 3 |
| Confluence 9.0 | EOL | Jul 30, 2024 | Jul 30, 2026 | Expired July 30, 2026 — twelve days ago |
| Confluence 8.9 | EOL | Apr 1, 2024 | Apr 2, 2026 | Last 8.x feature release |
| Confluence 8.5 | EOL | Aug 21, 2023 | Dec 15, 2025 | Former LTS; fix stream reached 8.5.31 |
Dates from our tracked dataset (verification pass 2026-08-11), cross-checked against Atlassian's end-of-life policy. Atlassian occasionally extends an LTS line slightly past two calendar years (Confluence 8.5 ran to December 15, 2025); we list the tracked dates. Badges and dates in these tables are re-verified against the data layer at every site build.
The Server ghost fleet: zero patches since February 15, 2024
Data Center is the treadmill; Server is the graveyard. Atlassian stopped selling new Server licenses on February 2, 2021, and on February 15, 2024 the line in its migration announcement came due: "support and bug fixes will no longer be available for your server products." Not "reduced support" — none, at any severity, for any Server product, forever.
That would be a routine end-of-life story if Server installs had actually disappeared. The exploitation record says they did not. Confluence Server's flaws keep being exploited years after disclosure — which only happens when unpatched instances remain reachable in numbers worth an attacker's time. Three Confluence entries in CISA's Known Exploited Vulnerabilities catalog — re-confirmed against the live catalog (2026-08-10 release) before publishing — carry the KEV field that matters most: known ransomware campaign use. And each one affects version lines that were already end of life when the fixes shipped, meaning the versions the ghost fleet actually runs never got, and never will get, a patch:
| CVE | Flaw | KEV listed | Ransomware use | Permanently unpatched on |
|---|---|---|---|---|
| CVE-2021-26084 | Unauthenticated OGNL injection → remote code execution (CVSS 9.8) | Nov 3, 2021 | Known | Confluence 6.0–6.12 (and older 4.x/5.x); fixes shipped only on 6.13, 7.4, 7.11, 7.12, 7.13 |
| CVE-2022-26134 | Unauthenticated OGNL injection → remote code execution (CVSS 9.8) | Jun 2, 2022 | Known | Confluence 6.x — Atlassian's advisory names every release after 1.3.0 as affected; fixes shipped only on 7.4 and 7.13–7.18 |
| CVE-2023-22518 | Improper authorization → unauthenticated instance reset and admin-account creation (CVSS 9.8; Atlassian revised to 10.0) | Nov 7, 2023 | Known | Confluence 5.x, 6.x, and every non-LTS 7.0–7.18 line; fixes shipped only on 7.19.16, 8.3.4, 8.4.4, 8.5.3, 8.6.1 |
Read that pattern once more, because it is the whole argument: three times in three consecutive years, a critical unauthenticated Confluence flaw was disclosed, mass-exploited, adopted by ransomware operators, and fixed only on the version lines still inside their two-year windows. Every line outside the window got silence. CVE-2023-22518 is the starkest case — an attacker needs no credentials to wipe a Confluence instance and create their own administrator account, ransomware groups picked it up within days of disclosure in November 2023, and on the 5.x, 6.x and non-LTS 7.x lines there is no patch to apply and never will be.
All three entries — with CVSS vectors, affected-version statements from Atlassian's own advisories, fixed-version lists, and the reasoning for why each qualifies as permanently unpatchable — are maintained in our Exploited & Unpatchable feed, the curated intersection of CISA's KEV catalog with end-of-life version data. It is also available as a free JSON feed. Confluence is one of the feed's most represented products — a distinction no vendor wants.
The operational takeaway for anyone who inherited an Atlassian estate: finding a Server instance is finding an incident waiting to be scheduled. The versions in the table above are exactly the versions a forgotten 2019-era Confluence Server runs. Scan for it the way the attackers do — it answers on the network, and every one of these CVEs has public, weaponized exploit code.
The decision fork: the treadmill, or the Cloud
Atlassian's self-hosted lifecycle now offers exactly two honest paths, and pretending there is a third — staying put — is how organizations end up in the table above.
Path 1 — run the Data Center treadmill deliberately. Accept the two-year cadence and plan around the LTS (Enterprise) releases: land on the current LTS — Jira 11.3 and Confluence 10.2, both supported to early December 2027 — and schedule the next hop before each window closes. This is a real, supported strategy; it simply has a recurring cost that perpetual-license Server never had, roughly one upgrade project per product per year to eighteen months. One caveat belongs in the plan: per our Atlassian Data Center tracker, Atlassian has closed Data Center to new customers (March 30, 2026), ends existing-customer renewals March 30, 2028, and has announced full Data Center end of life on March 28, 2029 — so the treadmill itself now has a published finish line, and a Data Center commitment made today is a bridge measured in single-digit years.
Path 2 — move to Atlassian Cloud. This is the destination Atlassian's own lifecycle decisions point toward, and it removes the version clock entirely — there is no version to be on. The trade-offs are the standard self-hosted-to-SaaS ones (data residency, compliance regimes, plugin/app parity, and pricing that scales differently than a perpetual license did), and they are real evaluation work rather than a footnote. What the Cloud path is not is optional to evaluate: with Server dead since 2024 and Data Center's own end of life announced, every Atlassian self-hosted roadmap now needs a written answer to "Cloud when, or off Atlassian to what?"
What is not a path is the status quo. The Server exploitation record above is what "we'll decide later" looks like three years on — and the Data Center two-year clock means "later" arrives on a schedule you can read off the tables in this article.
We track every Jira Software release, every Confluence release, the Atlassian Data Center platform dates, and 480+ other products against vendor-verified dates — check any version in seconds, or see what else hits end of life this quarter.
Confluence currently carries an EOL Risk Score™ of 35/100 — Grade B, moderate risk, recalculated at every site build from EOL recency, attack surface, CISA KEV exposure, and extended-support availability. Per-version scores and dates are on the Confluence lifecycle page.
The right response comes down to one question: how many more years does this system need to run? Under a year, extended support (where it exists) is usually cheaper than an emergency migration. One to three years, migrate — support fees paid repeatedly cost more than doing the project once. Indefinitely, migrate now and plan the next one before it surprises you. Extended support is often the more expensive choice over a multi-year horizon — a bridge, not a destination.
Frequently Asked Questions
How long does Atlassian support each Jira and Confluence Data Center version?
Two years, measured from that version's own release date. Atlassian's end-of-life policy states that it "supports releases for two years after the initial feature or Long-Term Support (LTS) release" — its own worked example: Jira Software Data Center 10.4.0 is supported until January 22, 2027 because it shipped January 22, 2025. So Jira Data Center 11.3 (released December 3, 2025) is supported until December 3, 2027, and Confluence 9.5 (released June 4, 2025) until June 4, 2027. There is no evergreen version: every release, LTS included, carries its own two-year clock.
Is Atlassian Server (Jira Server, Confluence Server) still supported?
No. Atlassian ended support for all Server products on February 15, 2024 — its announcement states that "support and bug fixes will no longer be available for your server products." New Server license sales had already stopped on February 2, 2021. Any organization still running Jira Server or Confluence Server in August 2026 has gone roughly two and a half years without a single security patch, and no future patch will ever come.
Which Jira and Confluence Data Center versions are still supported right now?
As of August 11, 2026, per our tracked data: Jira Software Data Center 10.0 through 11.3 are inside their two-year windows — but the oldest, Jira 10.0, reaches end of life on August 22, 2026. For Confluence Data Center, 9.1 through 10.2 are supported; Confluence 9.0 already reached end of life on July 30, 2026, and Confluence 9.1's window closes October 3, 2026. The current LTS releases are Jira 11.3 (supported to December 3, 2027) and Confluence 10.2 (supported to December 2, 2027).
Are old Confluence versions really still being exploited?
Yes — Confluence Server is among the most ransomware-targeted software in CISA's Known Exploited Vulnerabilities catalog. Three separate Confluence CVEs — CVE-2021-26084, CVE-2022-26134, and CVE-2023-22518 — are KEV-listed with known ransomware campaign use, and each affects version lines that were already end of life when the fixes shipped, so those versions will never receive a patch. All three are documented, with exact affected and fixed versions, in our Exploited & Unpatchable feed.
Related
- All Jira Software versions with live status · All Confluence versions · Atlassian Data Center platform dates
- Exploited & Unpatchable — every KEV-listed vulnerability that EOL versions will never get a fix for, including all three Confluence entries
- What Is LTS? Long-Term Support Explained — how two-year windows and LTS designations actually work
- The 2026 EOL Calendar — everything else with a 2026 date, including Jira 10.x's rolling expiries