Follow the latest coverage, related explainers and connected technology stories.
Attackers began targeting CVE-2026-21589 in eight self-hosted Atlassian products, including Jira, Confluence, and Bitbucket, hours after technical details and a public proof-of-concept tool were published. The flaw can be exploited without authentication to read specific files and, in some integrated Crowd environments, may lead to the creation of administrative accounts.