Why it matters
Organizations using affected Atlassian products should apply the patches to reduce the risk of sensitive application files being exposed.
Coverage 1 publisher
Articles stay on their publishers’ sites; each link opens the original.
Atlassian issues patches on October 5 for multiple products to address CVE-2026-21589, an arbitrary file access vulnerability. An attacker could read files in a web application’s directory, potentially exposing sensitive information such as configuration files.
Organizations using affected Atlassian products should apply the patches to reduce the risk of sensitive application files being exposed.
Articles stay on their publishers’ sites; each link opens the original.