bleeping-computer · Crawled Oct 7, 2026

Hackers exploit critical Atlassian flaw after public PoC release

3 IoCs
Read original article ↗

AI Summary

A critical unauthenticated file-access vulnerability, CVE-2026-21589, affecting multiple self-hosted Atlassian products including Jira, Confluence, and Bitbucket, is being actively exploited in the wild. The flaw allows attackers to perform directory traversal via a shared web-resource library that converts double colons into forward slashes, enabling unauthorized access to sensitive files such as crowd.properties containing plaintext credentials. Exploitation attempts were observed within hours of a public proof-of-concept release by watchTowr, and a Nuclei template has since been published, accelerating automated scanning and exploitation. Affected organizations are urged to patch immediately or apply mitigations such as WAF rules or network access restrictions.

AI-extracted · verify before operational use

Indicators of Compromise 3 extracted

Type Value Detail
IP 38[.]60[.]157[.]86 Details →
IP 146[.]70[.]187[.]234 Details →
IP 159[.]26[.]119[.]225 Details →