Hackers use Atlassian flaw CVE-2026-21589 in unauthenticated attacks
A public proof-of-concept exploit targets an arbitrary file-read vulnerability affecting self-managed Atlassian products, including Jira, Confluence and Bitbucket. BleepingComputer reports that attacks require no authentication. According to Cyber Security News, the flaw can expose sensitive application files and potentially give attackers Jira administrator access in environments integrated with Atlassian Crowd.
- Atlassian issued an out-of-band advisory on October 5, according to Cyber Security News.
Covered by 2 publishers within 1 hour of the first report.
Reporting2
BleepingComputer Hackers exploit critical Atlassian flaw after public PoC release · Bill Toulas
Cyber Security News PoC Exploit Released for Critical Atlassian Flaw That Can Lead to Jira Admin Access · Abinaya