Confluence Server End of Life: Two Years Past Support, Three Exploited CVEs, and No Patch Ever Coming
Confluence Server has been end of life since February 15, 2024. That is not a soft deadline or a "limited support" phase — it is Atlassian's stated end of support for the entire Server product line: no security patches, no bug fixes, no technical support, per the company's end-of-life policy. Two and a half years later, the instances still running are not merely unsupported. They are carrying some of the most heavily exploited vulnerabilities of the past five years — three CVEs that sit in CISA's Known Exploited Vulnerabilities catalog, every one of them flagged by CISA for known ransomware campaign use — and no version of Confluence that is past end of life will ever receive a fix for the ones it missed.
This article documents the pattern, because it repeated three times on this one product and it will repeat again: in 2021, 2022, and 2023, a critical Confluence vulnerability was disclosed, exploitation followed (or preceded) the disclosure, and Atlassian shipped fixes only for the branches it supported at that moment. Each wave stranded every branch that had already died. Three waves, same lesson — and the lesson has a forward edge, because under Atlassian's current Data Center policy, every version gets exactly two years from its own release date. Today's supported branch is tomorrow's unpatchable one.
Wave one, 2021: CVE-2021-26084 — and everything before 6.13 is left behind
On August 25, 2021, Atlassian published a security advisory for CVE-2021-26084, an OGNL expression-injection flaw allowing unauthenticated remote code execution. NVD rates it 9.8 Critical. Exploitation was widespread enough that CISA added it to the KEV catalog on November 3, 2021 — and CISA's live catalog entry today carries the flag it reserves for confirmed ransomware association: known ransomware campaign use.
The advisory's affected list reached far down the version history — the 4.x, 5.x and 6.0–6.12 lines are all named among affected versions. The fixed builds, however, landed on exactly five branches: 6.13.23, 7.4.11, 7.11.6, 7.12.5, and 7.13.0 — the branches Atlassian supported at the time. The 6.0–6.12 lines were already past end of life at disclosure, and they received no fixed build. Not then, not since, not ever. That entry — with sources — is in our Exploited & Unpatchable feed today.
Wave two, 2022: CVE-2022-26134 — same flaw class, same triage, new casualties
Ten months later it happened again, faster. On June 2, 2022, Atlassian published an advisory for CVE-2022-26134 — another unauthenticated OGNL injection, another 9.8-rated remote code execution, this time already being exploited in the wild as the advisory went out. CISA added it to the KEV catalog the same day, June 2, 2022. It, too, carries CISA's known-ransomware-campaign-use flag today.
The affected statement was about as broad as an affected statement can be: all supported versions, and every Confluence release after 1.3.0. The fixes shipped to the branches alive that week: 7.4.17 on the LTS line, and 7.13.7, 7.14.3, 7.15.2, 7.16.4, 7.17.4, 7.18.1 across the current branches. Confluence 6.x — named as affected, already dead — got nothing. A 6.x server that survived wave one unpatched now carried two permanent, actively-exploited RCEs.
Wave three, 2023: CVE-2023-22518 — the ransomware wave
The third wave is the one that turned "unpatched Confluence" into a ransomware business model. CVE-2023-22518 is an improper-authorization flaw that lets an unauthenticated attacker reset a Confluence instance and create their own administrator account — full compromise, no credentials required. NVD rates it 9.8; Atlassian took the unusual step of revising its own severity rating to 10.0, the top of the scale, as exploitation escalated (see Atlassian's advisory). CISA added it to the KEV catalog on November 7, 2023, and it has been mass-exploited — including by ransomware operators — since November 2023.
The fix list is five builds long: 7.19.16 on the 7.x LTS line, and 8.3.4, 8.4.4, 8.5.3, 8.6.1. Everything else named in the advisory's "all versions prior to the fixed releases" — every non-LTS 7.x branch from 7.0 through 7.18, all of 6.x, all of 5.x — received no fixed build. That includes branches that had done everything right up to that point. Which brings us to 7.13.
The scoreboard: three waves, one pattern
CVE details from Atlassian's advisories and our Exploited & Unpatchable feed; KEV dates and ransomware flags re-verified against CISA's live catalog (version 2026.08.11) on August 12, 2026.
| Wave | CVE | What it is | Severity | KEV added | Fixed only on | Left permanently vulnerable |
|---|---|---|---|---|---|---|
| 2021 | CVE-2021-26084 | Unauthenticated OGNL injection → RCE | 9.8 (NVD) | Nov 3, 2021 | 6.13, 7.4, 7.11, 7.12, 7.13 branches | 6.0–6.12 (4.x/5.x also named affected) |
| 2022 | CVE-2022-26134 | Unauthenticated OGNL injection → RCE | 9.8 (NVD) | Jun 2, 2022 | 7.4 and 7.13–7.18 branches | 6.x (every release after 1.3.0 affected) |
| 2023 | CVE-2023-22518 | Improper authorization → instance reset, attacker-created admin account | 9.8 (NVD); 10.0 (Atlassian, revised) | Nov 7, 2023 | 7.19.16, 8.3.4, 8.4.4, 8.5.3, 8.6.1 | 7.0–7.18 (non-LTS), 6.x, 5.x |
All three entries carry CISA's "known" flag for ransomware campaign use in the live KEV catalog. "Left permanently vulnerable" lists the end-of-life branches that were named as affected and never received a fixed build, per each Atlassian advisory — branches that did receive a per-branch backport are excluded.
Read the table cumulatively and the arithmetic is stark. A Confluence 6.x server (6.0–6.12) running today carries all three — two unauthenticated remote-code-execution flaws and an unauthenticated admin takeover, every one KEV-listed, every one ransomware-associated, none of them ever to be patched. Every non-LTS 7.x branch through 7.18 carries the admin takeover at minimum. Even the branches that were patched against their contemporary waves — 7.13 most instructively — carry whichever wave arrived after their death. The only Confluence installations with zero permanent exposure from this list are the ones that kept moving to supported branches. That is the entire lesson.
Why this keeps happening: the lifecycle math
None of the three waves involved Atlassian behaving unusually. Vendors fix supported versions; that is what "supported" means, and it is the industry norm, not an Atlassian quirk — why end of life is inevitable walks through the economics. What makes Confluence a uniquely clean case study is that its lifecycle produced three natural experiments in three consecutive years, on the same product, with the same result each time.
Two clocks govern your exposure, per our tracked lifecycle data and Atlassian's end-of-life policy:
The Server clock already rang. Confluence Server — the perpetual-license deployment — lost all support on February 15, 2024, along with every other Atlassian Server product, Jira Server included. New Server license sales had already ended on February 2, 2021. There is no supported Server version to move to; the platform itself is the EOL unit. Our companion piece, Atlassian's Two-Year Treadmill, covers that shutdown and the full Jira and Confluence Data Center version tables — we won't duplicate them here.
The Data Center clock rings every two years, per version. Each Data Center release is supported for two years from its own release date. There is no evergreen tier: 8.5 LTS died December 15, 2025; 9.0 died July 30, 2026; 9.1 dies October 3, 2026. The five fixed versions from the 2023 wave — the ones that were the safe destination — are all on branches that have since reached end of life themselves. Being patched against the last wave is not the same as being eligible for a patch in the next one. When wave four arrives, the fix list will name whatever branches are alive that week, and every branch that died between now and then joins the permanent list.
Where the branches stand today
| Branch | Status | Released | End of life | Permanent KEV exposure (from the three waves) |
|---|---|---|---|---|
| 10.2 (LTS) | Supported | Dec 2, 2025 | Dec 2, 2027 | None — current LTS |
| 9.2 (LTS) | Warning | Dec 9, 2024 | Dec 10, 2026 | None |
| 9.1 | EOL Oct 3, 2026 | Oct 3, 2024 | Oct 3, 2026 | None — yet |
| 8.5 (LTS) | EOL | Aug 21, 2023 | Dec 15, 2025 | None from these waves (8.5.3 fixed 2023's) — ineligible for the next |
| 7.19 (LTS) | EOL | Jul 27, 2022 | Dec 13, 2024 | None from these waves (7.19.16 fixed 2023's) — ineligible for the next |
| 7.13 (LTS) | EOL | Aug 15, 2021 | Aug 17, 2023 | CVE-2023-22518 — forever |
| 7.4 (LTS) | EOL | Apr 18, 2020 | Apr 21, 2022 | CVE-2023-22518 — forever |
| 7.0–7.18 (non-LTS) | EOL | — | All by May 30, 2024 (7.18, the last) | CVE-2023-22518 — forever |
| 6.0–6.12 | EOL | — | All past EOL before the Aug 2021 advisory | All three CVEs — forever |
| Confluence Server (any version, Server license) | EOL Feb 15, 2024 | — | Feb 15, 2024 | Everything disclosed since Feb 2024, plus the applicable waves above |
Branch dates from our tracked lifecycle data (re-verified nightly against the upstream endoflife.date dataset, which cites Atlassian's documentation); Server platform date from Atlassian's end-of-support announcements. "Ineligible for the next" means the branch is past end of life and will not be named in future fix lists — the 7.13 pattern, one wave later.
What to actually do
If you are on Confluence Server (any version): the migration decision was made for you in February 2024; what remains is executing it. The supported destinations are Data Center — currently the 10.2 LTS line, supported to December 2, 2027 — or Atlassian Cloud. Until the migration lands, treat the instance as compromised-adjacent: take it off the public internet, put authentication in front of it, and check it for attacker-created administrator accounts — the specific artifact CVE-2023-22518 exploitation leaves behind.
If you are on an EOL Data Center branch: same destinations, shorter distance. Upgrading from 8.x or 9.0 to a supported branch is a version upgrade, not a platform migration — the cheapest it will ever be is now, before wave four names its fix list without you.
If you are on 9.1: you have until October 3, 2026. Move to 9.2 LTS (supported to December 10, 2026) only as a stepping stone — 10.2 LTS is the destination that buys actual runway.
We track Confluence and 480+ other products against vendor-verified dates — every Confluence version with live status and risk score, all of Atlassian's tracked products in one place, or check your exact version in seconds.
Confluence currently carries an EOL Risk Score™ of 35/100 — Grade B, moderate risk, recalculated at every site build from EOL recency, attack surface, CISA KEV exposure, and extended-support availability. Per-version scores and dates are on the Confluence lifecycle page.
The right response comes down to one question: how many more years does this system need to run? Under a year, extended support (where it exists) is usually cheaper than an emergency migration. One to three years, migrate — support fees paid repeatedly cost more than doing the project once. Indefinitely, migrate now and plan the next one before it surprises you. Extended support is often the more expensive choice over a multi-year horizon — a bridge, not a destination. And if this deadline feels like vendor caprice, it isn’t — why end of life is inevitable for every version, with the receipts.
Frequently Asked Questions
Is Confluence Server end of life?
Yes. Atlassian ended support for all Server products — Confluence Server included — on February 15, 2024, per its published end-of-support policy and announcements. No security patches, bug fixes, or technical support of any kind have shipped for Confluence Server since that date, and none ever will. New Server license sales had already stopped on February 2, 2021. Confluence continues only as Data Center (self-hosted, with each version supported for two years from its own release date) and Cloud.
Is Jira Server end of life too?
Yes — the February 15, 2024 end of support covered Atlassian's entire Server product line, not just Confluence: Jira Software Server, Jira Service Management Server, Confluence Server, Bitbucket Server, and the rest all lost support the same day. A Jira Server instance running today is in exactly the position this article describes for Confluence: any vulnerability disclosed after February 2024 will only ever be fixed in Data Center or Cloud. Our companion piece on Atlassian's two-year Data Center treadmill has the full Jira version tables.
I'm running Confluence 7.13 — am I affected?
Yes, permanently. Confluence 7.13 was an LTS branch, released August 15, 2021, and it weathered the first two exploitation waves: 7.13.0 shipped with the fix for CVE-2021-26084, and 7.13.7 carried the fix for CVE-2022-26134. But the branch reached end of life on August 17, 2023 — its final release was 7.13.20, on August 2, 2023 — and when CVE-2023-22518 arrived that autumn, the fixes went only to 7.19.16, 8.3.4, 8.4.4, 8.5.3 and 8.6.1. A fully patched 7.13.20 instance is an unauthenticated-admin-takeover target with known ransomware campaign use, and no 7.13 fix will ever exist. Dates and live status: Confluence 7.13.
Which Confluence versions are actually safe to run today?
Only a currently-supported Data Center branch. Per our tracked lifecycle data, Confluence Data Center 9.1 through 10.2 are supported as of August 2026, with 10.2 (an LTS release, supported to December 2, 2027) as the current long-term line. Note that the fixed versions from the 2023 wave — 7.19.16, 8.3.4, 8.4.4, 8.5.3, 8.6.1 — are not safe harbors anymore: every one of those branches has itself since reached end of life under Atlassian's two-year-per-version policy. Being patched against the last wave is not the same as being eligible for a patch in the next one. The next supported branch to fall is 9.1, on October 3, 2026.
Related
- All Confluence versions with live status · Confluence 7.13 — dates and risk score · All Atlassian products we track
- Atlassian's Two-Year Treadmill — the full Jira and Confluence Data Center version tables, and the February 2024 Server shutdown in detail
- Exploited & Unpatchable — the verified feed of KEV-listed vulnerabilities that end-of-life versions will never get fixes for, including all three Confluence entries
- Why End of Life Is Inevitable — the economics behind "fixes ship only to supported branches," with the receipts
- The Jenkins CVE that made every old LTS permanently vulnerable — the same rolling-window lesson, twelve weeks at a time