SecurityWeek

Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication


Threat actors have started targeting CVE-2026-21589, a critical vulnerability in Atlassian’s self-hosted Data Center products. The attacks began shortly after technical details went public.

Atlassian disclosed the bug on October 5 and gave it a CVSS score of 9.3. It affects Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye. Patches have been released for all affected versions.

The flaw lets remote, unauthenticated attackers access specific files in the web application’s root directory. “Exploitation requires prior knowledge of the target file’s exact name and path,” Atlassian notes, adding that the vulnerability can’t be used to list directory contents.

WatchTowr published its analysis on October 6. The researchers traced the issue to a library that the affected products share. 

According to WatchTowr, the bigger risk shows up when Jira is integrated with Crowd, Atlassian’s identity management product. In that setup, an attacker can read a configuration file that stores Crowd application credentials in plaintext.

WatchTowr used those credentials to create a new user and add it to the Jira administrators group. The researchers described direct Crowd access with leaked credentials as “basically game over.” 

Advertisement. Scroll to continue reading.

Exploitation intelligence firm Previdian says its honeypots began recording CVE-2026-21589 exploitation attempts on October 6, hours after WatchTowr’s findings went public. As of October 8, Previdian had logged 190 attempts from 32 IP addresses in 10 countries.

CISA has not yet added CVE-2026-21589 to its Known Exploited Vulnerabilities catalog.

Organizations are advised to update to the fixed versions. If they can’t patch right away, they should cut the instances off from the internet or apply the firewall and rewrite rules Atlassian provided.

Related: TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws

Related: FortiBleed Attackers Locking Victims Out of Fortinet Devices

Related: SonicWall and Splunk Patch Critical Vulnerabilities



Source link