Follow the latest coverage, related explainers and connected technology stories.
Attackers began targeting CVE-2026-21589 in eight self-hosted Atlassian products, including Jira, Confluence, and Bitbucket, hours after technical details and a public proof-of-concept tool were published. The flaw can be exploited without authentication to read specific files and, in some integrated Crowd environments, may lead to the creation of administrative accounts.
Atlassian released security updates to address CVE-2026-21589, rated critical at 9.3 under CVSS, which could allow an unauthenticated attacker to access specific files in the root path of web applications. The company recommends isolating internet-accessible deployments or updating them immediately, although there is no evidence that the vulnerability has been actively exploited so far.