Follow the latest coverage, related explainers and connected technology stories.
Attackers began targeting CVE-2026-21589 in eight self-hosted Atlassian products, including Jira, Confluence, and Bitbucket, hours after technical details and a public proof-of-concept tool were published. The flaw can be exploited without authentication to read specific files and, in some integrated Crowd environments, may lead to the creation of administrative accounts.
Atlassian released security updates to address CVE-2026-21589, rated critical at 9.3 under CVSS, which could allow an unauthenticated attacker to access specific files in the root path of web applications. The company recommends isolating internet-accessible deployments or updating them immediately, although there is no evidence that the vulnerability has been actively exploited so far.
Atlassian describes rebuilding its incident-detection platform using OpenTelemetry, Apache Kafka, and Apache Flink on Kubernetes, reducing the time required to turn events into metrics to less than 10 seconds and lowering operating costs by approximately 97%. However, the improvement did not eliminate coverage and false-alarm problems, nor the ingestion pipeline’s dependence on a single region.