Back to advisories

Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details

A critical arbitrary file access vulnerability (CVE-2026-21589) in Atlassian Data Center products is under active exploitation as of public disclosure. Threat actors attempted exploitation within two hours of details going public, with potential access to credentials and sensitive files. All Atlassian Data Center instances are at risk until patched.

CRITICALAdvisoryOct 08, 2026
Action required
Immediately patch all Atlassian Data Center deployments to the latest patched version. If patching cannot be done today, implement the vendor-provided mitigation steps and hunt for exploitation attempts targeting CVE-2026-21589 in web logs and network traffic.
Affected products
Bitbucket Data CenterConfluence Data CenterJira Service Management Data CenterJira Software Data CenterBamboo Data Center