Tag

Cve 2026 21589

All articles tagged with #cve 2026 21589

Atlassian CVE-2026-21589 Exploitation Surges After Public PoC Enables Admin Takeover
cybersecurity2 days ago

Atlassian CVE-2026-21589 Exploitation Surges After Public PoC Enables Admin Takeover

A critical, unauthenticated file-access vulnerability in eight Atlassian Data Center products is being actively exploited. The flaw, CVE-2026-21589, allows attackers to read specific files in the web root if they know the exact path. In Crowd-integrated deployments, this can lead to full administrator takeover. Exploitation attempts began within two hours of a public proof-of-concept release.

Atlassian CVE-2026-21589: Critical File-Read Flaw in Eight Data Center Products Faces Rapid Exploitation
security2 days ago

Atlassian CVE-2026-21589: Critical File-Read Flaw in Eight Data Center Products Faces Rapid Exploitation

Atlassian disclosed a critical vulnerability, CVE-2026-21589, affecting eight self-hosted Data Center products. The flaw allows unauthenticated attackers to read specific files in the web root if they know the exact path. While Atlassian initially reported no evidence of exploitation, security firms confirmed active attempts within hours of technical details emerging. Cloud users are patched, but self-hosted admins must update immediately or apply temporary mitigations.

Atlassian patches critical unauthenticated file-read flaw across eight self-hosted products
security3 days ago

Atlassian patches critical unauthenticated file-read flaw across eight self-hosted products

Atlassian disclosed CVE-2026-21589 on October 5, a critical path traversal flaw affecting eight self-hosted Data Center products. The vulnerability allows unauthenticated attackers to read specific files in the web application root directory if they know the exact file path. Atlassian rated the flaw 9.3/10 on the CVSS scale. Cloud versions are already patched, but self-hosted users must upgrade to specific fixed versions or apply temporary mitigations. Atlassian has not confirmed active exploitation but advises users to check logs for suspicious requests.