Critical Atlassian vulnerability affects Jira, Confluence and other products

Rapid7 has published an Emergent Threat Response (ETR) alert for a critical vulnerability, tracked as CVE-2026-21589, affecting eight Atlassian products including Jira, Confluence, Bitbucket and Crowd.

Critical Atlassian vulnerability affects Jira, Confluence and other products

Critical Atlassian vulnerability affects Jira, Confluence and other products


Rapid7 has published an Emergent Threat Response (ETR) alert for a critical vulnerability, tracked as CVE-2026-21589, affecting eight Atlassian products including Jira, Confluence, Bitbucket and Crowd.

Rapid7 rated the vulnerability 9.3 (critical) and said it could allow unauthenticated remote attackers to access sensitive files within affected applications, potentially exposing credentials and other confidential information.

The alert noted that technical details and proof-of-concept exploit code are now publicly available. Rapid7 urged organisations to patch affected systems immediately, outside normal patching cycles, and to review access logs for signs of attempted exploitation.

Rapid7 said the issue affects Atlassian Data Center and other self-managed products, while Atlassian Cloud customers have already been protected through vendor updates.

Rapid7’s advisory, including affected products and mitigation guidance, is available at: https://www.rapid7.com/blog/post/etr-cve-2026-21589-critical-unauthenticated-arbitrary-file-access-in-atlassian-products/

About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.