Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication

Threat actors have started targeting CVE-2026-21589, a critical vulnerability in Atlassian’s self-hosted Data Center products.

Atlassian

Threat actors have started targeting CVE-2026-21589, a critical vulnerability in Atlassian’s self-hosted Data Center products. The attacks began shortly after technical details went public.

Atlassian disclosed the bug on October 5 and gave it a CVSS score of 9.3. It affects Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye. Patches have been released for all affected versions.

The flaw lets remote, unauthenticated attackers access specific files in the web application’s root directory. “Exploitation requires prior knowledge of the target file’s exact name and path,” Atlassian notes, adding that the vulnerability can’t be used to list directory contents.

WatchTowr published its analysis along with PoC code on October 6. The researchers traced the issue to a library that the affected products share. 

According to WatchTowr, the bigger risk shows up when Jira is integrated with Crowd, Atlassian’s identity management product. In that setup, an attacker can read a configuration file that stores Crowd application credentials in plaintext.

WatchTowr used those credentials to create a new user and add it to the Jira administrators group. The researchers described direct Crowd access with leaked credentials as “basically game over.” 

Advertisement. Scroll to continue reading.

Exploitation intelligence firm Previdian says its honeypots began recording CVE-2026-21589 exploitation attempts on October 6, hours after WatchTowr’s findings went public. As of October 8, Previdian had logged 190 attempts from 32 IP addresses in 10 countries.

CISA has not yet added CVE-2026-21589 to its Known Exploited Vulnerabilities catalog.

Organizations are advised to update to the fixed versions. If they can’t patch right away, they should cut the instances off from the internet or apply the firewall and rewrite rules Atlassian provided.

Related: TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws

Related: FortiBleed Attackers Locking Victims Out of Fortinet Devices

Related: SonicWall and Splunk Patch Critical Vulnerabilities

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Rapid7 has named Rik Ferguson as VP of Security Intelligence.

Cytactic has appointed Tim Brown as CSO.

Scott Simkin has joined Vega as CMO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.