Self-hosted Atlassian Data Center products have an unauthenticated file-read bug, CVE-2026-21589, scored CVSS 9.3. Attackers started probing it within hours of a public technical write-up.
What happened
Atlassian disclosed the issue on 5 October 2026. A remote attacker who already knows the exact path can read specific files inside the web application root. The bug does not list directory contents.
watchTowr published analysis and proof-of-concept code on 6 October. Previdian honeypots recorded exploitation attempts the same day. As of 8 October, Previdian had logged 190 attempts from 32 addresses in 10 countries. CISA has not added this CVE to the Known Exploited Vulnerabilities catalog. That is not a reason to wait.
The sharp case is Jira integrated with Crowd. The readable file can hold Crowd application credentials in plaintext. watchTowr used those credentials to create a user and place it in the Jira administrators group.
Who is affected
Atlassian Cloud is already patched. No Cloud customer action is required. Every listed self-hosted product, on all versions before the fixed builds, is in scope.
- Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, and Crowd Data Center.
- Crucible and Fisheye.
- Highest practical risk: internet-facing Jira that trusts Crowd, because one properties file can become an admin account.
What to do now
Patch each self-hosted instance to a fixed version, or cut it off from the internet until you do.
- Jira Software and Jira Service Management Data Center: 9.12.40, 10.3.26, or 11.3.12. Jira Service Management also has 5.12.40.
- Confluence Data Center: 9.2.26 or 10.2.19. Bitbucket Data Center: 9.4.26, 10.2.8, or 10.5.1.
- Bamboo Data Center: 10.2.24 or 12.1.12. Crowd Data Center: 6.3.7, 7.0.3, 7.1.7, or 7.2.4. Crucible and Fisheye: 4.9.15.
- If Jira is integrated with Crowd and the instance was reachable, rotate the Crowd application credentials and review admin users created since 6 October.
Source: SecurityWeek, Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication.
Also on the blog
- CVE-2026-107406: NetScaler SAML RCE at CVSS 9.5
- AhsayCBS CVE-2026-105134: SYSTEM RCE, 5 organizations hit
- FBI seizes 7 Flax Typhoon domains used for Microscan and FishHub
- CVE-2026-106126: Tenable Identity Exposure SYSTEM injection, CVSS 9.9
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.