Back to Feed
VulnerabilitiesOct 7, 2026

Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details

Atlassian Data Center products exploited for arbitrary file access within two hours of public details.

Summary

A critical arbitrary file access vulnerability (CVE-2026-21589) in Atlassian Data Center products is being actively exploited. Threat actors began attempting to exploit the flaw within two hours of public disclosure, potentially accessing sensitive files like credentials. Atlassian has released patches for affected products and recommends mitigation steps for those unable to patch immediately.

Full text

Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details Ravie LakshmananOct 07, 2026Vulnerability / Web Security Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. "This arbitrary file access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions," the Australian company said. "Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be sensitive files present that increase your risk." Atlassian said impacted Atlassian Cloud products have been patched, adding that fixes are available for the following products - Bitbucket Data Center - 9.4.26, 10.2.8, and 10.5.1 Confluence Data Center - 9.2.26 and 10.2.19 Jira Service Management Data Center - 5.12.40, 10.3.26, and 11.3.12 Jira Software Data Center - 9.12.40, 10.3.26, and 11.3.12 Bamboo Data Center - 10.2.24 and 12.1.12 Crowd Data Center - 6.3.7, 7.0.3, 7.1.7, and 7.2.4 Crucible - 4.9.15 Fisheye - 4.9.15 As temporary mitigation, Atlassian is recommending that customers remove their instance from the public internet, apply a Web Application Firewall (WAF) rule, block requests using Tomcat's RewriteValve (for Confluence, JSM, Jira, Bamboo, and Crowd), and add a new rule to urlrewrite.xml (for Bitbucket). According to telemetry data from Previdian, a total of 15 exploitation attempts have been detected from three unique IP addresses located in Japan and the U.S. - 38.60.157[.]86 146.70.187[.]234 159.26.119[.]225 The exploitation activity targeting its honeypot network is said to have begun two hours after watchTowr released additional technical details of the vulnerability, stating it allows unauthenticated attackers to retrieve sensitive files within the webroot directory through a single request and extract tokens, credentials, keys, or other authentication material. According to the preemptive exposure management firm, the underlying vulnerability has to do with Atlassian's web-resource handling, which converts a string like "..::..::..::..::WEB-INF::web.xml" to "../../../../WEB-INF/web.xml." As a result, an unauthenticated attacker with knowledge of the resource-resolution logic can abuse this path resolution logic and combine it with an Atlassian "/includes/jquery/plugins/colorpicker/images/" plugin resource by taking advantage of the trailing "/" to reach other files (e.g., "WEB-INF/web.xml") elsewhere in the application - GET /download/resources/jira.webresources:color-picker-popup/images/..::..::..::..::..::WEB-INF::web.xml HTTP/1.1 Host: {{Jira-Hostname}} Importantly, in the case of Atlassian Crowd and Jira, the attacker could exploit the flaw to access "WEB-INF/classes/crowd.properties," which stores Crowd credentials, and then use them to gain administrative access to the application. Armed with this privileged access, it's possible to create new users, modify user privileges, and elevate a newly created rogue user to Jira Administrator. "Within two hours of public exploit details becoming available, we were already seeing exploitation attempts hit our honeypot network," Previdian Founder and CEO Ryan Dewhurst said in a statement shared with The Hacker News. "The release of a Nuclei template will make mass automated scanning even easier, so we expect activity around CVE-2026-21589 to increase quickly. Organizations running affected Atlassian products should treat patching as an immediate priority." Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Atlassian, Vulnerability, Web Security ⚡ Top Stories This Week ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members How Financial Services Companies Can Modernize Their Software Supply Chain US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access Zero Trust for AI Agents Starts With Fixing Zero Visibility ⭐ Featured Resources Discover Hidden AI Agents and Lock Down Their Access — Get a Demo The CISO Playbook for Board-Ready Security Reporting The Browser Attacks Your Security Stack Is Missing 41 Cybersecurity Courses. One Week to Level Up Your Skills

Indicators of Compromise

  • cve — CVE-2026-21589
  • ip — 38.60.157.86
  • ip — 146.70.187.234
  • ip — 159.26.119.225

Entities

Bitbucket Data Center (product)Confluence Data Center (product)Jira Service Management Data Center (product)Jira Software Data Center (product)Bamboo Data Center (product)Crowd Data Center (product)