Attackers target Atlassian file-access flaw CVE-2026-21589
The critical vulnerability affects multiple Atlassian Data Center products and can expose sensitive files under certain conditions. Tracked as CVE-2026-21589, it carries a CVSS score of 9.3. According to The Hacker News, affected products include Bitbucket Data Center, Confluence Data Center and Jira Service Management Data Center.
- The Hacker News reports exploitation attempts began within two hours of public disclosure.
Covered by 3 publishers within 26 hours of the first report.
Reporting3
The Hacker News Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details · info@thehackernews.com (The Hacker News)
Security Affairs Atlassian Vulnerability Comes Under Attack Hours After Details Go Public · Pierluigi Paganini
SecurityWeek Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication · Eduard Kovacs
Related
Topics Data centers