Atlassian CVE-2026-21589 Exploited Hours After Details Go Public
Attackers are exploiting CVE-2026-21589 (CVSS 9.3), an arbitrary file access flaw in Atlassian Data Center products that lets unauthenticated attackers read files in the webroot. Affected products include Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible and Fisheye; honeypot exploitation began about two hours after watchTowr published its analysis.
- CVE-2026-21589 (CVSS 9.3) allows unauthenticated reading of files in the webroot
- Affected: Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible and Fisheye
- Honeypot exploitation began about two hours after watchTowr's analysis
- In one Crowd deployment with Jira, crowd.properties was read and jira-administrators access gained
Read next
Security