endoflife.ai
EOL Checker Products EOL Watch Get Support

Confluence Server End of Life: Two Years Past Support, Three Exploited CVEs, and No Patch Ever Coming

By Scott Bissett  ·  Published: August 12, 2026  ·  EOL Watch — security analysis  ·  All three CVEs re-verified against CISA's live Known Exploited Vulnerabilities catalog (version 2026.08.11) on August 12, 2026; lifecycle dates verified against our tracked data, which traces to Atlassian's published end-of-support policy — methodology

Confluence Server has been end of life since February 15, 2024. That is not a soft deadline or a "limited support" phase — it is Atlassian's stated end of support for the entire Server product line: no security patches, no bug fixes, no technical support, per the company's end-of-life policy. Two and a half years later, the instances still running are not merely unsupported. They are carrying some of the most heavily exploited vulnerabilities of the past five years — three CVEs that sit in CISA's Known Exploited Vulnerabilities catalog, every one of them flagged by CISA for known ransomware campaign use — and no version of Confluence that is past end of life will ever receive a fix for the ones it missed.

This article documents the pattern, because it repeated three times on this one product and it will repeat again: in 2021, 2022, and 2023, a critical Confluence vulnerability was disclosed, exploitation followed (or preceded) the disclosure, and Atlassian shipped fixes only for the branches it supported at that moment. Each wave stranded every branch that had already died. Three waves, same lesson — and the lesson has a forward edge, because under Atlassian's current Data Center policy, every version gets exactly two years from its own release date. Today's supported branch is tomorrow's unpatchable one.

The one-sentence status check: If your Confluence is a Server license — any version — it has received nothing since February 15, 2024 and never will again. If it is Data Center on a branch older than 9.1, that branch is also past end of life per our tracked lifecycle data. Either way, at least one of the three KEV-listed CVEs below may apply to you permanently, depending on your branch — the wave-by-wave record shows exactly which.

Wave one, 2021: CVE-2021-26084 — and everything before 6.13 is left behind

On August 25, 2021, Atlassian published a security advisory for CVE-2021-26084, an OGNL expression-injection flaw allowing unauthenticated remote code execution. NVD rates it 9.8 Critical. Exploitation was widespread enough that CISA added it to the KEV catalog on November 3, 2021 — and CISA's live catalog entry today carries the flag it reserves for confirmed ransomware association: known ransomware campaign use.

The advisory's affected list reached far down the version history — the 4.x, 5.x and 6.0–6.12 lines are all named among affected versions. The fixed builds, however, landed on exactly five branches: 6.13.23, 7.4.11, 7.11.6, 7.12.5, and 7.13.0 — the branches Atlassian supported at the time. The 6.0–6.12 lines were already past end of life at disclosure, and they received no fixed build. Not then, not since, not ever. That entry — with sources — is in our Exploited & Unpatchable feed today.

Running Confluence past end of life?
Extended support past the official EOL date exists for many products in this position — whether it covers Confluence is exactly what we check. Tell us where to reach you and we’ll reply with matched options and pricing guidance — or an honest “no vendor covers this.” Free, no obligation.

Free · No obligation · Independent — we track the dates, vendors don’t pay for placement · dates verified against vendor sources. See all support options →

Wave two, 2022: CVE-2022-26134 — same flaw class, same triage, new casualties

Ten months later it happened again, faster. On June 2, 2022, Atlassian published an advisory for CVE-2022-26134 — another unauthenticated OGNL injection, another 9.8-rated remote code execution, this time already being exploited in the wild as the advisory went out. CISA added it to the KEV catalog the same day, June 2, 2022. It, too, carries CISA's known-ransomware-campaign-use flag today.

The affected statement was about as broad as an affected statement can be: all supported versions, and every Confluence release after 1.3.0. The fixes shipped to the branches alive that week: 7.4.17 on the LTS line, and 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4, 7.18.1 across the current branches. Confluence 6.x — named as affected, already dead — got nothing. A 6.x server that survived wave one unpatched now carried two permanent, actively-exploited RCEs.

Wave three, 2023: CVE-2023-22518 — the ransomware wave

The third wave is the one that turned "unpatched Confluence" into a ransomware business model. CVE-2023-22518 is an improper-authorization flaw that lets an unauthenticated attacker reset a Confluence instance and create their own administrator account — full compromise, no credentials required. NVD rates it 9.8; Atlassian took the unusual step of revising its own severity rating to 10.0, the top of the scale, as exploitation escalated (see Atlassian's advisory). CISA added it to the KEV catalog on November 7, 2023, and it has been mass-exploited — including by ransomware operators — since November 2023.

The fix list is five builds long: 7.19.16 on the 7.x LTS line, and 8.3.4, 8.4.4, 8.5.3, 8.6.1. Everything else named in the advisory's "all versions prior to the fixed releases" — every non-LTS 7.x branch from 7.0 through 7.18, all of 6.x, all of 5.x — received no fixed build. That includes branches that had done everything right up to that point. Which brings us to 7.13.

The 7.13 lesson — patching perfectly is not enough. Confluence 7.13 was an LTS branch and a good citizen: 7.13.0 shipped with the wave-one fix, 7.13.7 carried the wave-two fix. Then the branch reached its end of life on August 17, 2023 — final release 7.13.20, on August 2, 2023 — and wave three arrived roughly three months later. The fixes went to 7.19 and 8.x. A fully patched, final-release 7.13.20 instance today is an unauthenticated admin-takeover target with known ransomware campaign use, permanently. If you searched for "Confluence 7.13 release notes" hoping for a newer build: 7.13.20 was the last one, three years ago, and there will never be another. Dates and status: Confluence 7.13 lifecycle page.

The scoreboard: three waves, one pattern

CVE details from Atlassian's advisories and our Exploited & Unpatchable feed; KEV dates and ransomware flags re-verified against CISA's live catalog (version 2026.08.11) on August 12, 2026.

WaveCVEWhat it isSeverityKEV addedFixed only onLeft permanently vulnerable
2021CVE-2021-26084Unauthenticated OGNL injection → RCE9.8 (NVD)Nov 3, 20216.13, 7.4, 7.11, 7.12, 7.13 branches6.0–6.12 (4.x/5.x also named affected)
2022CVE-2022-26134Unauthenticated OGNL injection → RCE9.8 (NVD)Jun 2, 20227.4 and 7.13–7.18 branches6.x (every release after 1.3.0 affected)
2023CVE-2023-22518Improper authorization → instance reset, attacker-created admin account9.8 (NVD); 10.0 (Atlassian, revised)Nov 7, 20237.19.16, 8.3.4, 8.4.4, 8.5.3, 8.6.17.0–7.18 (non-LTS), 6.x, 5.x

All three entries carry CISA's "known" flag for ransomware campaign use in the live KEV catalog. "Left permanently vulnerable" lists the end-of-life branches that were named as affected and never received a fixed build, per each Atlassian advisory — branches that did receive a per-branch backport are excluded.

Read the table cumulatively and the arithmetic is stark. A Confluence 6.x server (6.0–6.12) running today carries all three — two unauthenticated remote-code-execution flaws and an unauthenticated admin takeover, every one KEV-listed, every one ransomware-associated, none of them ever to be patched. Every non-LTS 7.x branch through 7.18 carries the admin takeover at minimum. Even the branches that were patched against their contemporary waves — 7.13 most instructively — carry whichever wave arrived after their death. The only Confluence installations with zero permanent exposure from this list are the ones that kept moving to supported branches. That is the entire lesson.

Why this keeps happening: the lifecycle math

None of the three waves involved Atlassian behaving unusually. Vendors fix supported versions; that is what "supported" means, and it is the industry norm, not an Atlassian quirk — why end of life is inevitable walks through the economics. What makes Confluence a uniquely clean case study is that its lifecycle produced three natural experiments in three consecutive years, on the same product, with the same result each time.

Two clocks govern your exposure, per our tracked lifecycle data and Atlassian's end-of-life policy:

The Server clock already rang. Confluence Server — the perpetual-license deployment — lost all support on February 15, 2024, along with every other Atlassian Server product, Jira Server included. New Server license sales had already ended on February 2, 2021. There is no supported Server version to move to; the platform itself is the EOL unit. Our companion piece, Atlassian's Two-Year Treadmill, covers that shutdown and the full Jira and Confluence Data Center version tables — we won't duplicate them here.

The Data Center clock rings every two years, per version. Each Data Center release is supported for two years from its own release date. There is no evergreen tier: 8.5 LTS died December 15, 2025; 9.0 died July 30, 2026; 9.1 dies October 3, 2026. The five fixed versions from the 2023 wave — the ones that were the safe destination — are all on branches that have since reached end of life themselves. Being patched against the last wave is not the same as being eligible for a patch in the next one. When wave four arrives, the fix list will name whatever branches are alive that week, and every branch that died between now and then joins the permanent list.

Where the branches stand today

BranchStatusReleasedEnd of lifePermanent KEV exposure (from the three waves)
10.2 (LTS)SupportedDec 2, 2025Dec 2, 2027None — current LTS
9.2 (LTS)WarningDec 9, 2024Dec 10, 2026None
9.1EOL Oct 3, 2026Oct 3, 2024Oct 3, 2026None — yet
8.5 (LTS)EOLAug 21, 2023Dec 15, 2025None from these waves (8.5.3 fixed 2023's) — ineligible for the next
7.19 (LTS)EOLJul 27, 2022Dec 13, 2024None from these waves (7.19.16 fixed 2023's) — ineligible for the next
7.13 (LTS)EOLAug 15, 2021Aug 17, 2023CVE-2023-22518 — forever
7.4 (LTS)EOLApr 18, 2020Apr 21, 2022CVE-2023-22518 — forever
7.0–7.18 (non-LTS)EOLAll by May 30, 2024 (7.18, the last)CVE-2023-22518 — forever
6.0–6.12EOLAll past EOL before the Aug 2021 advisoryAll three CVEs — forever
Confluence Server (any version, Server license)EOL Feb 15, 2024Feb 15, 2024Everything disclosed since Feb 2024, plus the applicable waves above

Branch dates from our tracked lifecycle data (re-verified nightly against the upstream endoflife.date dataset, which cites Atlassian's documentation); Server platform date from Atlassian's end-of-support announcements. "Ineligible for the next" means the branch is past end of life and will not be named in future fix lists — the 7.13 pattern, one wave later.

What to actually do

If you are on Confluence Server (any version): the migration decision was made for you in February 2024; what remains is executing it. The supported destinations are Data Center — currently the 10.2 LTS line, supported to December 2, 2027 — or Atlassian Cloud. Until the migration lands, treat the instance as compromised-adjacent: take it off the public internet, put authentication in front of it, and check it for attacker-created administrator accounts — the specific artifact CVE-2023-22518 exploitation leaves behind.

If you are on an EOL Data Center branch: same destinations, shorter distance. Upgrading from 8.x or 9.0 to a supported branch is a version upgrade, not a platform migration — the cheapest it will ever be is now, before wave four names its fix list without you.

If you are on 9.1: you have until October 3, 2026. Move to 9.2 LTS (supported to December 10, 2026) only as a stepping stone — 10.2 LTS is the destination that buys actual runway.

We track Confluence and 480+ other products against vendor-verified datesevery Confluence version with live status and risk score, all of Atlassian's tracked products in one place, or check your exact version in seconds.

What to do about it

Confluence currently carries an EOL Risk Score™ of 35/100 — Grade B, moderate risk, recalculated at every site build from EOL recency, attack surface, CISA KEV exposure, and extended-support availability. Per-version scores and dates are on the Confluence lifecycle page.

The right response comes down to one question: how many more years does this system need to run? Under a year, extended support (where it exists) is usually cheaper than an emergency migration. One to three years, migrate — support fees paid repeatedly cost more than doing the project once. Indefinitely, migrate now and plan the next one before it surprises you. Extended support is often the more expensive choice over a multi-year horizon — a bridge, not a destination. And if this deadline feels like vendor caprice, it isn’t — why end of life is inevitable for every version, with the receipts.

Frequently Asked Questions

Is Confluence Server end of life?

Yes. Atlassian ended support for all Server products — Confluence Server included — on February 15, 2024, per its published end-of-support policy and announcements. No security patches, bug fixes, or technical support of any kind have shipped for Confluence Server since that date, and none ever will. New Server license sales had already stopped on February 2, 2021. Confluence continues only as Data Center (self-hosted, with each version supported for two years from its own release date) and Cloud.

Is Jira Server end of life too?

Yes — the February 15, 2024 end of support covered Atlassian's entire Server product line, not just Confluence: Jira Software Server, Jira Service Management Server, Confluence Server, Bitbucket Server, and the rest all lost support the same day. A Jira Server instance running today is in exactly the position this article describes for Confluence: any vulnerability disclosed after February 2024 will only ever be fixed in Data Center or Cloud. Our companion piece on Atlassian's two-year Data Center treadmill has the full Jira version tables.

I'm running Confluence 7.13 — am I affected?

Yes, permanently. Confluence 7.13 was an LTS branch, released August 15, 2021, and it weathered the first two exploitation waves: 7.13.0 shipped with the fix for CVE-2021-26084, and 7.13.7 carried the fix for CVE-2022-26134. But the branch reached end of life on August 17, 2023 — its final release was 7.13.20, on August 2, 2023 — and when CVE-2023-22518 arrived that autumn, the fixes went only to 7.19.16, 8.3.4, 8.4.4, 8.5.3 and 8.6.1. A fully patched 7.13.20 instance is an unauthenticated-admin-takeover target with known ransomware campaign use, and no 7.13 fix will ever exist. Dates and live status: Confluence 7.13.

Which Confluence versions are actually safe to run today?

Only a currently-supported Data Center branch. Per our tracked lifecycle data, Confluence Data Center 9.1 through 10.2 are supported as of August 2026, with 10.2 (an LTS release, supported to December 2, 2027) as the current long-term line. Note that the fixed versions from the 2023 wave — 7.19.16, 8.3.4, 8.4.4, 8.5.3, 8.6.1 — are not safe harbors anymore: every one of those branches has itself since reached end of life under Atlassian's two-year-per-version policy. Being patched against the last wave is not the same as being eligible for a patch in the next one. The next supported branch to fall is 9.1, on October 3, 2026.

Related

The Monthly EOL Digest™

Once a month — critical EOL dates, CVE blind spots, and lifecycle changes worth knowing.

© 2026 endoflife.ai · How we verify our dates · API · About · Data from endoflife.date (MIT)