Attackers target Atlassian file-access flaw CVE-2026-21589

First reported by The Hacker News at · Updated · 3 sources

The critical vulnerability affects multiple Atlassian Data Center products and can expose sensitive files under certain conditions. Tracked as CVE-2026-21589, it carries a CVSS score of 9.3. According to The Hacker News, affected products include Bitbucket Data Center, Confluence Data Center and Jira Service Management Data Center.

  • The Hacker News reports exploitation attempts began within two hours of public disclosure.

Covered by 3 publishers within 26 hours of the first report.

Reporting3

The Hacker News Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details · info@thehackernews.com (The Hacker News)
Security Affairs Atlassian Vulnerability Comes Under Attack Hours After Details Go Public · Pierluigi Paganini

Related

Topics Data centers