Home · Wiki · Incidents & Campaigns
type: incident · created: 2026-10-07 · updated: 2026-10-07 · tags: [incident, global] · confidence: high · severity: medium · affected_sectors: [global] · au_impact: true

Atlassian disclosed CVE-2026-21589, a critical (9.3 / CVSS 4.0) flaw letting unauthenticated attackers read specific files from the web-application root of its Data Centre products — Jira Software, Confluence, Bitbucket, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye. Exploiting it requires knowing a file's exact name and path, so it cannot list directory contents, but Atlassian notes its products install to well-documented default locations and that some configurations leave sensitive files exposed. Fixed releases were listed per product on 6 October; the cloud line is already patched with no evidence of cloud exploitation. For unpatched internet-facing instances Atlassian's first recommendation is to take them offline, and it provided WAF, Tomcat RewriteValve and Bitbucket urlrewrite.xml mitigation rules plus access-log search guidance. It also flagged CVE-2021-26086, a prior Jira path traversal, as precedent for attackers exploiting this class in the wild.

Attribute Detail
Sector Global (Macro)
Date 2026-10-07
Source iTnews
Reliability Tier 3
CVEs CVE-2021-26086, CVE-2026-21589