Security

Atlassian warns of critical file-access flaw as attackers begin exploitation

Atlassian’s CVE-2026-21589 affects multiple self-hosted Data Center products, including Jira, Confluence, and Bitbucket, and allows arbitrary or specific-file access. Multiple reports say exploitation has begun; one describes attacks as unauthenticated, while another says access requires knowing a file’s exact name and path and does not allow directory listing.

Image: The Register

Why it matters

The reports describe active exploitation of a critical flaw in widely used self-hosted collaboration and development products, making customer response time-sensitive.

What we know

Confirmed by several sources

Reported by one source

Open questions

Coverage 3 publishers

  1. BleepingComputer

    Hackers exploit critical Atlassian flaw after public PoC release

  2. The Register

    Atlassian warns of critical file access flaw in its datacenter products

  3. The Hacker News

    Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details

Articles stay on their publishers’ sites; each link opens the original.