TL;DR
Attackers have begun CVE-2026-21589 exploitation against self-managed Atlassian servers. Researchers at watchTowr published a full technical breakdown and working proof-of-concept for the arbitrary file read flaw. Days later, threat intelligence firm Previdian Cyber reported honeypot traffic matching the bug. Admins who have not patched Jira, Confluence, Bitbucket or related products should do so now.
- CVE: CVE-2026-21589
- CVSS: 9.3 (Critical · CVSSv4)
- Product: Atlassian Bamboo Data Center
- Affected: All other versions
- Status: Exploited in the wild
- PoC: Available (Nuclei)
- Patched in: Patch version 10.2.24 and later, Patch version 12.1.12 and later, Patch version 10.2.8 and later, Patch version 10.5.1 and later (+12 more)
- EPSS: 0.7% (30-day)
- Action: Update to Patch version 10.2.24 and later, Patch version 12.1.12 and later, Patch version 10.2.8 and later, Patch version 10.5.1 and later (+12 more) now
Running Infra, AppSec, and SOC teams? Tag Atlassian alerts by team automatically.
Try Team free for 14 daysWhy It Matters
This flaw needs no login and no user interaction. Atlassian rates it 9.3 on CVSS, and it hits eight self-managed products at once. The Atlassian security advisory covers Jira, Jira Service Management, Confluence, Bitbucket, Bamboo, Crowd, Fisheye and Crucible.
The scale is large. The watchTowr Labs analysis notes that a quick internet search turned up “just under 700,000 instances of Confluence alone.” As a result, CVE-2026-21589 exploitation threatens a wide pool of exposed servers, not a narrow slice.
How the Attack Works
The bug lives in a shared web-resource library that several Atlassian products use. A routing function fails to fully sanitize a user-supplied resource path. According to watchTowr, that gap lets an attacker read files “within the web application root directory” without logging in first.
watchTowr also showed that file read alone can go further. On products that ship Crowd, an attacker who reads the right configuration file can gain access to Crowd’s administrative API. From there, the researchers describe a path to full administrative control, though Atlassian notes that exploitation “requires prior knowledge of the target file’s exact name and path.”
Exploitation Status
CVE-2026-21589 exploitation is now confirmed outside the lab. Previdian Cyber says its honeypot network has observed “attacker IPs exploiting Atlassian (CVE-2026-21589),” and the firm adds that “a Nuclei template has also now been released.” Previdian expects attack volume to keep climbing.
Separately, watchTowr has released a detection tool on GitHub so defenders can check whether an instance is vulnerable. Atlassian’s own advisory states that cloud products are patched and shows no exploitation there, but it predates these honeypot reports for self-managed servers.
Affected Versions
Every version of each product is affected, including end-of-life releases. Fixed versions include Jira Data Center 9.12.40, 10.3.26 or 11.3.12; Confluence Data Center 9.2.26 or 10.2.19; Bitbucket Data Center 9.4.26, 10.2.8 or 10.5.1; Bamboo Data Center 10.2.24 or 12.1.12; Crowd Data Center 6.3.7, 7.0.3, 7.1.7 or 7.2.4; and Fisheye and Crucible 4.9.15.
Patch and Mitigation Steps
Upgrade to a fixed version immediately. With active scanning and a public Nuclei template in circulation, delay carries real risk.
Monitor logs for the IP addresses Previdian Cyber has shared from its honeypot network, since repeat requests from those sources point to active scanning. Teams that cannot patch right away should pull exposed instances off the internet first. Next, apply Atlassian’s web application firewall rule to block path traversal patterns, or use the RewriteValve and urlrewrite.xml options the advisory describes. These steps only reduce risk, so patching stays the priority while CVE-2026-21589 exploitation continues.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!