
Atlassian CVE-2026-21589 Exploitation Surges After Public PoC Enables Admin Takeover
A critical, unauthenticated file-access vulnerability in eight Atlassian Data Center products is being actively exploited. The flaw, CVE-2026-21589, allows attackers to read specific files in the web root if they know the exact path. In Crowd-integrated deployments, this can lead to full administrator takeover. Exploitation attempts began within two hours of a public proof-of-concept release.

