Attackers exploit critical Atlassian file-access flaw affecting Data Center products
Reports say attackers are exploiting Atlassian vulnerability CVE-2026-21589, a critical file-access flaw affecting self-hosted Data Center products including Jira, Confluence, and Bitbucket. Coverage describes unauthenticated access to specific files, while one report notes that exploitation requires knowing a file’s exact name and path and does not allow directory listing.