Atlassian patched CVE-2026-21589, a critical arbitrary-file-access bug scored CVSS 9.3. An unauthenticated attacker who already knows a file name and path can read that file from the web application root. The bug does not let the attacker list the directory.
What happened
Atlassian and WatchTowr both say there is no evidence of exploitation in the wild. That is not a reason to wait. Eight Atlassian flaws are already on CISA's Known Exploited Vulnerabilities list, and this class of bug has been used by ransomware crews and espionage groups against collaboration servers before.
WatchTowr's Yordan Ganchev warned that sites using Crowd for single sign-on should be especially careful. Authentication details can sit in plaintext at a predictable path. If Crowd is reachable, that file is enough to mint an administrator.
Who is affected
Self-hosted Data Center and server products, not Atlassian Cloud. All versions of these eight products are in scope until the fixed build for that branch is installed:
- Bitbucket Data Center: 9.4.26, 10.2.8, 10.5.1.
- Confluence Data Center: 9.2.26, 10.2.19.
- Jira Software Data Center: 9.12.40, 10.3.26, 11.3.12.
- Jira Service Management Data Center: 5.12.40, 10.3.26, 11.3.12.
- Bamboo Data Center: 10.2.24, 12.1.12.
- Crowd Data Center: 6.3.7, 7.0.3, 7.1.7, 7.2.4.
- Crucible 4.9.15 and Fisheye 4.9.15.
What to do now
Patch the fixed build for each product, or remove the instance from the internet until that patch is on. Atlassian says public instances, including ones that already require a login, should be cut off from external access until you can act. If Crowd fronts SSO, treat that host as the priority.
Source: SecurityWeek, Atlassian Patches Critical Vulnerability Affecting 8 Products.
Also on the blog
- CVE-2026-88779 crashes SAML NetScaler, patch by 7 October
- GitLab AI Gateway sandbox escape is a 9.9, patches are out
- Ninja Forms CVE-2026-94504 exploited on a plugin used by 500,000 sites
- Dell DSU CVE-2026-86360 (CVSS 9.6) root on PowerEdge updates
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.