Skip to content
feed: live
0dayNews
atlassian
● Breaking

Atlassian CVE-2026-21589: Exploits Active, Patch Now

Active exploitation of CVE-2026-21589 began within hours of a public PoC. All eight affected Atlassian Data Center products need patching immediately.

Atlassian CVE-2026-21589: Exploits Active, Patch Now
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
fuseMarisol "Fuse" Delgado·Published ·1 min read

CVE-2026-21589 is under active exploitation. BleepingComputer and The Hacker News report that attack attempts against unpatched Atlassian Data Center instances began within two hours of a public proof-of-concept circulating. If your instance isn’t patched, it’s exposed.

What changed

0dayNews covered the initial advisory when Atlassian released patches on October 6. At that point, Atlassian reported no evidence of active exploitation. That window has closed. A proof-of-concept went public October 7, and exploitation attempts followed almost immediately, according to The Hacker News.

The flaw: CVSS 9.3 unauthenticated path traversal across eight Data Center products. No credentials needed. An attacker with network access can read files from each product’s web application root directory. Self-hosted Data Center deployments only; Atlassian-managed cloud instances are not affected.

Patch now

Fixed versions released October 6:

  • Bitbucket Data Center: 9.4.26, 10.2.8, 10.5.1
  • Confluence Data Center: 9.2.26, 10.2.19
  • Jira Software Data Center: 9.12.40, 10.3.26, 11.3.12
  • Jira Service Management Data Center: 5.12.40, 10.3.26, 11.3.12
  • Bamboo Data Center: 10.2.24, 12.1.12
  • Crowd Data Center: 6.3.7, 7.0.3, 7.1.7, 7.2.4
  • Crucible: 4.9.15
  • Fisheye: 4.9.15

If you can’t patch immediately, the Atlassian advisory has WAF and reverse proxy blocking rules, plus Tomcat and urlrewrite.xml mitigations for Confluence and Jira. Those are stopgaps, not substitutes for patching.

Rapid7’s exploit threat report covers indicators and detection guidance for confirming whether your instance was probed. Full CVE details and affected version matrix on our CVE-2026-21589 page. For context on Atlassian’s pattern of high-severity Data Center flaws, see also: Rejetto HFS RCE Under Active Exploitation and SailPoint Patches Critical Unauth RCE in IdentityIQ.

Related CVEs
  • [ CRITICAL ]CVE-2026-21589Path traversal allows unauthenticated file read in eight Atlassian Data Center products

Found this useful? Share it.