Don’t do SECURITY. Do business SECURELY.

Urgent: Atlassian Data Center vulnerability under active attack

Atlassian Data Center flaw CVE-2026-21589 (Jira, Confluence, Bitbucket, and more) is being exploited: upgrade self-hosted instances now or restrict internet access.

Urgent awareness alert. This is awareness content, not a monitored threat intelligence service: always check vendor advisories against your own environment.

Atlassian has fixed a critical vulnerability (CVE-2026-21589, CVSS 9.3) in its self-hosted Data Center products: Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo, Crowd, Crucible, and Fisheye. All versions before the fixed releases are affected. An unauthenticated attacker who knows a file’s exact name and path can read files in the application’s web root directory, and some configurations keep sensitive files there, such as credentials stored by Crowd. Security researchers report that exploitation attempts began within about two hours of technical details being published, and they expect scanning to increase. Atlassian has patched its Cloud products, so Cloud customers do not need to act.

What to do:

  • Upgrade every self-hosted instance to a fixed release from Atlassian’s advisory (for example Confluence 9.2.26 or 10.2.19, Jira Software 9.12.40, 10.3.26, or 11.3.12, and Bitbucket 9.4.26, 10.2.8, or 10.5.1), starting with internet-facing instances.
  • If you cannot upgrade straight away, apply Atlassian’s mitigations on every node: a web application firewall or proxy rule that blocks the path traversal patterns, or the Tomcat or Bitbucket rewrite rules.
  • Check for compromise: search your access logs for the traversal patterns described in the advisory, and involve your security team if you find any.
  • Restrict exposure: take instances off the public internet where you can, including those that require users to log in.

Source: Atlassian security advisory: CVE-2026-21589 arbitrary file access vulnerability

If you would like help assessing your exposure, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with a link to our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights