Hackers exploit critical Atlassian flaw after public PoC release
AI Summary
A critical unauthenticated file-access vulnerability, CVE-2026-21589, affecting multiple self-hosted Atlassian products including Jira, Confluence, and Bitbucket, is being actively exploited in the wild. The flaw allows attackers to perform directory traversal via a shared web-resource library that converts double colons into forward slashes, enabling unauthorized access to sensitive files such as crowd.properties containing plaintext credentials. Exploitation attempts were observed within hours of a public proof-of-concept release by watchTowr, and a Nuclei template has since been published, accelerating automated scanning and exploitation. Affected organizations are urged to patch immediately or apply mitigations such as WAF rules or network access restrictions.
AI-extracted · verify before operational use