Critical Atlassian Data Center Vulnerability CVE-2026-21589 Exploited Within Two Hours of Disclosure
A critical arbitrary file access vulnerability (CVE-2026-21589, CVSS 9.3) in Atlassian Data Center products enables unauthenticated attackers to access sensitive files through path traversal, with exploitation attempts detected within two hours of public disclosure. Affected products include Bitbucket, Confluence, Jira, and others, requiring immediate patching and mitigation measures.
Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions.
The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software
*** END OF TRANSMISSION ***