Atlassian has released patches for CVE-2026-21589, a critical arbitrary-file-access vulnerability with a CVSS score of 9.3. The flaw affects all versions of Bitbucket Data Center, Bamboo Data Center, Crowd Data Center, Crucible, Confluence Data Center, Fisheye, Jira Service Management Data Center and Jira Software Data Center. An unauthenticated attacker must know the exact name and path of the target file; the flaw does not provide directory listing or enumeration.
Fixes are available in updated releases across the affected products, and Atlassian advises organizations to patch self-hosted deployments promptly or disconnect internet-exposed instances until remediation is possible. The vendor and WatchTowr report no evidence of exploitation in the wild, but warn that sensitive files and exposed Crowd authentication data could increase impact. Temporary mitigations and WAF rules are recommended where immediate patching is not possible.
https://www.securityweek.com/atlassian-patches-critical-vulnerability-affecting-8-products/
Fixes are available in updated releases across the affected products, and Atlassian advises organizations to patch self-hosted deployments promptly or disconnect internet-exposed instances until remediation is possible. The vendor and WatchTowr report no evidence of exploitation in the wild, but warn that sensitive files and exposed Crowd authentication data could increase impact. Temporary mitigations and WAF rules are recommended where immediate patching is not possible.
https://www.securityweek.com/atlassian-patches-critical-vulnerability-affecting-8-products/