chiprook
← Security
SecurityOctober 8, 2026, 14:26

Atlassian CVE-2026-21589 Exploited Hours After Details Go Public

Attackers are exploiting CVE-2026-21589 (CVSS 9.3), an arbitrary file access flaw in Atlassian Data Center products that lets unauthenticated attackers read files in the webroot. Affected products include Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible and Fisheye; honeypot exploitation began about two hours after watchTowr published its analysis.

Atlassian CVE-2026-21589 Exploited Hours After Details Go Public
#Atlassian#Confluence#Jira#Bitbucket
Read next
Security

Atlassian warns of critical file access flaw in datacenter products

Security

MCP Atlassian Falls Back to Operator Credentials Without Verified Identity

Software

Atlassian opens Jira Automation Rules management API

Security

ZoomEye: 1.8M Confluence matches depend on which fingerprint you use