Atlassian CVE-2026-21589 exploited: patch Jira and Confluence
Attackers hit Atlassian CVE-2026-21589, an unauthenticated file read in self-hosted Jira, Confluence and Bitbucket, hours after a PoC. Fixed versions and steps.
If you still run Jira, Confluence or Bitbucket on your own server, stop and check your version. Atlassian CVE-2026-21589 is an unauthenticated file-read flaw with a CVSS v4.0 score of 9.3. It hits eight self-hosted Data Center and Server products. A public proof of concept came out on October 6, and attack attempts started within hours. CISA has not listed it as known-exploited yet. Do not wait for that.
What actually happened
Atlassian published its security advisory on October 5. An attacker with no login can request specific files inside the application's web root. Atlassian says the attacker must know the exact file name and path, and cannot list directories.
That limit matters less than it sounds. Per SecurityWeek, researchers at watchTowr showed that when Jira is connected to Crowd, a config file holds the Crowd application credentials in plain text. With those, they created a user and added it to the Jira administrators group. File read became admin access.
watchTowr published its analysis and PoC on October 6. Previdian's honeypots logged the first attempts the same day. By October 8 it counted 190 attempts from 32 IP addresses in 10 countries. Atlassian says it has no evidence of exploitation against customers.
Affected products: Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye. Fixed versions, from watchTowr's FAQ:
- Jira Software / Jira Service Management: 9.12.40 / 5.12.40, 10.3.26, 11.3.12
- Confluence: 9.2.26, 10.2.19
- Bitbucket: 9.4.26, 10.2.8, 10.5.1
- Crowd: 6.3.7, 7.0.3, 7.1.7, 7.2.4
- Bamboo: 10.2.24, 12.1.12 · Crucible / Fisheye: 4.9.15
The advisory covers self-hosted products only. Atlassian Cloud is not listed.
Why it matters for your business
Your Jira and Confluence hold more than tickets. They hold API keys pasted into pages, deploy notes, customer data and the map of your systems. A file read on that box can leak the credentials to everything else.
What we would do today:
- Patch to a fixed version. That is the only real fix.
- If you cannot patch tonight, pull it off the public internet. Put it behind a VPN or an IP allowlist. Atlassian's WAF and rewrite rules are a stopgap, not a fix.
- Rotate secrets. If the instance was exposed since October 6, assume config files were read. Rotate Crowd app passwords, database credentials and any tokens in the web root.
- Search your access logs for path traversal: two dots next to a slash, backslash or double colon, after URL-decoding.
- Audit your admin groups for accounts nobody remembers creating.
Key takeaways
- CVE-2026-21589 is an unauthenticated file read in eight self-hosted Atlassian products, CVSS 9.3
- Attack attempts began hours after the October 6 public PoC
- Jira plus Crowd setups can leak plaintext credentials that lead to admin access
- Patch now, or take the instance off the public internet until you can
- Rotate secrets and check admin groups if you were exposed after October 6
Still running a self-hosted tool you forgot about? We map what your business exposes to the internet, patch or retire it, and move secrets out of wiki pages and config files. Book an exposure review, or see what we build and maintain.
Sources: Atlassian, SecurityWeek, watchTowr.
- #security
- #atlassian
- #jira
- #confluence
- #patching
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
NetScaler CVE-2026-107406: last week's SAML patch isn't enough
Citrix NetScaler CVE-2026-107406 (CVSS 9.5) hits SAML IdP builds up to 14.1-73.41, the fix for last week's KEV bug. Patch to 14.1-73.46 or 13.1-64.29.
Read itHarness buys Augment Code assets: coding agents consolidate
Harness bought Augment Code's Cosmos, Auggie CLI and Context Engine. Coding agent vendors are consolidating. Keep your context and workflow portable.
Read it