Cybersecurity DEVELOPING
Atlassian warns of critical file-access flaw in Jira, Confluence
First reported Source: BleepingComputerLast editorial activity
What happened
Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589 (the public catalogue number for a specific software flaw), that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket. Atlassian is a software company based in Sydney, founded in 2002, which employed about 8,200 people in 2022, and its products and services include productivity software.
Sources & evidence
- BleepingComputer Reporting source
Atlassian warns of critical file-access flaw in Jira, Confluence ↗
https://www.bleepingcomputer.com/news/security/atlassian-warns-of-critical-file-access-flaw-in-jira-confluence/