Atlassian flaw under active attack exposes files across eight Data Center products
Atlassian’s CVE-2026-21589 is a critical, unauthenticated file-read flaw affecting eight self-managed Data Center products, including Jira, Confluence and Bitbucket. Security researchers reported active exploitation; Previdian telemetry recorded 15 attempts from three IP addresses in Japan and the US, while Atlassian advised customers to patch or apply temporary mitigations.
Bottom line — The flaw carries a CVSS score of 9.3, and Atlassian says customers should check affected installations for signs of compromise.
Go deeper 6
-
Infosecurity Magazine reports that attackers can read specific files in an application’s web root, but need to know the exact file path.
-
WatchTowr found that the vulnerable path-handling logic sits in a shared Atlassian web-resource library used by the affected products.
-
In a Crowd deployment linked to Jira, WatchTowr retrieved credentials that could be used to create a user and add it to a group.
-
Security Affairs reports exploitation attempts against WatchTowr’s honeypots began about two hours after its technical analysis was published.
-
Atlassian’s temporary advice includes removing affected instances from the public internet or blocking malicious requests with a web application firewall.
-
WatchTowr released a tool to check Jira, Confluence and Bitbucket instances; Atlassian says it cannot confirm whether individual customers were affected.