Active exploitation hits Atlassian flaw CVE-2026-21589 after PoC release
Security firm Previdian detected exploitation attempts against CVE-2026-21589, an unauthenticated arbitrary file-access vulnerability affecting eight self-hosted Atlassian products including Jira, Confluence, and Bitbucket, shortly after watchTowr published a technical report explaining the bug. The flaw stems from a shared web-resource library that mishandles double-colon characters, letting attackers craft directory-traversal requests through plugin endpoints to read protected files without logging in. Atlassian had already issued an advisory urging administrators to patch self-hosted instances, saying it cannot confirm which customer deployments may already be compromised.