Vulnerabilities

Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication

Threat actors have started targeting CVE-2026-21589, a critical vulnerability in Atlassian’s self-hosted Data Center products.

Atlassian

Threat actors have started targeting CVE-2026-21589, a critical vulnerability in Atlassian’s self-hosted Data Center products. The attacks began shortly after technical details went public.

Atlassian disclosed the bug on October 5 and gave it a CVSS score of 9.3. It affects Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye. Patches have been released for all affected versions.

The flaw lets remote, unauthenticated attackers access specific files in the web application’s root directory. “Exploitation requires prior knowledge of the target file’s exact name and path,” Atlassian notes, adding that the vulnerability can’t be used to list directory contents.

WatchTowr published its analysis along with PoC code on October 6. The researchers traced the issue to a library that the affected products share. 

According to WatchTowr, the bigger risk shows up when Jira is integrated with Crowd, Atlassian’s identity management product. In that setup, an attacker can read a configuration file that stores Crowd application credentials in plaintext.

WatchTowr used those credentials to create a new user and add it to the Jira administrators group. The researchers described direct Crowd access with leaked credentials as “basically game over.” 

Advertisement. Scroll to continue reading.

Exploitation intelligence firm Previdian says its honeypots began recording CVE-2026-21589 exploitation attempts on October 6, hours after WatchTowr’s findings went public. As of October 8, Previdian had logged 190 attempts from 32 IP addresses in 10 countries.

CISA has not yet added CVE-2026-21589 to its Known Exploited Vulnerabilities catalog.

Organizations are advised to update to the fixed versions. If they can’t patch right away, they should cut the instances off from the internet or apply the firewall and rewrite rules Atlassian provided.

Related: TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws

Related: FortiBleed Attackers Locking Victims Out of Fortinet Devices

Related: SonicWall and Splunk Patch Critical Vulnerabilities

Related Content

Vulnerabilities

The security defect, tracked as CVE-2026-107406, could lead to remote code execution or denial-of-service.

Vulnerabilities

The security defects could lead to unauthorized access, information leaks, privilege escalation, DoS attacks, and remote code execution.

Vulnerabilities

Critical and high-severity vulnerabilities could allow attackers to bypass authentication, execute arbitrary code, and elevate their privileges.

Government

SEC Consult has published technical details on vulnerabilities mentioned in a complaint filed by several US states.

Vulnerabilities

Four critical-severity use-after-free defects were fixed in Chromecast, Browser, Navigation, and Track.

Mobile & Wireless

The patches resolve a critical vulnerability in Android’s System component that could lead to privilege escalation.

Vulnerabilities

Unauthenticated attackers could exploit the flaw to access specific files in the web application root directory.

Vulnerabilities

CVE-2026-61500 allows attackers to recover the session-cookie signing key and gain administrative access and RCE.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version