Vulnerabilities

Atlassian Patches Critical Vulnerability Affecting 8 Products

Unauthenticated attackers could exploit the flaw to access specific files in the web application root directory.

Atlassian

Atlassian has rolled out patches for a critical-severity vulnerability that impacts all versions of eight of its products.

The security defect, tracked as CVE-2026-21589 (CVSS score of 9.3), is described as an arbitrary file access issue.

It can be exploited without authentication to access specific files in the web application root directory.

“Exploitation requires prior knowledge of the target file’s exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be sensitive files present that increase your risk,” Atlassian notes in its advisory.

All versions of Bitbucket Data Center, Bamboo Data Center, Crowd Data Center, Crucible, Confluence Data Center, Fisheye, Jira Service Management Data Center, and Jira Software Data Center are impacted, the company says.

Fixes were included in Bitbucket versions 9.4.26, 10.2.8, and 10.5.1; Bamboo versions 10.2.24 and 12.1.12; Confluence versions 9.2.26 and 10.2.19; Crowd versions 6.3.7, 7.0.3, 7.1.7, and 7.2.4; Crucible version 4.9.15; Fisheye version 4.9.15; Jira Service Management versions 5.12.40, 10.3.26, and 11.3.12; and Jira versions 9.12.40, 10.3.26, and 11.3.12.

Advertisement. Scroll to continue reading.

Organizations are advised to patch their self-hosted deployments as soon as possible or disconnect their instances from the internet until the fixes can be installed. Atlassian’s advisory also details temporary mitigations.

“Instances accessible to the public internet, including those with user authentication, should be restricted from external network access until you can take action,” the company notes.

Both Atlassian and preemptive exposure management firm WatchTowr note that there is no evidence of CVE-2026-21589 being exploited in the wild.

According to WatchTowr, however, ransomware groups and APTs have exploited this type of vulnerability in the past, and eight Atlassian security flaws are currently on CISA’s KEV list.

“Organizations that have SSO enabled through Crowd, which is the recommended approach, should be extra cautious. The authentication details are stored in plaintext in a predictable, known path and can be trivially extracted. With these, attackers can mint their own admin users and gain access should Crowd endpoints be remotely accessible,” WatchTowr principal threat intelligence specialist Yordan Ganchev said.

“Organizations running any of the eight affected Atlassian products on-site should patch immediately. Where patching is not immediately possible, users should follow vendor guidance on deploying WAF rules to block exploitation attempts,” Ganchev added.

Related: Exploitation Hits Rejetto HFS Vulnerability Discovered by AI

Related: Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Related: Fortra Patches Critical Vulnerabilities in BoKS

Related: Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

Related Content

Vulnerabilities

Threat actors have started targeting CVE-2026-21589, a critical vulnerability in Atlassian’s self-hosted Data Center products.

Vulnerabilities

Critical and high-severity vulnerabilities could allow attackers to bypass authentication, execute arbitrary code, and elevate their privileges.

Government

SEC Consult has published technical details on vulnerabilities mentioned in a complaint filed by several US states.

Vulnerabilities

Four critical-severity use-after-free defects were fixed in Chromecast, Browser, Navigation, and Track.

Mobile & Wireless

The patches resolve a critical vulnerability in Android’s System component that could lead to privilege escalation.

Vulnerabilities

CVE-2026-61500 allows attackers to recover the session-cookie signing key and gain administrative access and RCE.

Vulnerabilities

Citrix has confirmed that a new zero-day vulnerability, CVE-2026-88779, emerged just days after two other exploited flaws were patched.

Vulnerabilities

The bugs could lead to authentication bypass, shell command execution, and memory corruption.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version