CVE-2025-35115: Atlassian Agiloft

High severity, CVSS 8.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Agiloft Release 28 downloads critical system packages over an insecure HTTP connection. An attacker in a Man-In-the-Middle position could replace or modify the contents of the download URL. Users should upgrade to Agiloft Release 30.

Affected products

  • Atlassian Agiloft: from 19, before 30 (fixed in 30)

Published 2025-08-26. Last modified 2026-06-17.