Critical Atlassian Vulnerability (CVE-2026-21589) Under Active Exploitation After Patch Release
Atlassian has released patches for a critical arbitrary file access vulnerability, CVE-2026-21589, affecting multiple self-hosted Data Center products including Confluence, Jira, and Bitbucket. One day after the patches were released, exploitation attempts against the flaw have already begun. The vulnerability, rated 9.3 (critical), allows unauthenticated attackers to access specific files within the web application root directory.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.
Open NewsSnap.ai