Index
Search
Search the public record. Drafts and scheduled notes are not included.
Critical
news
Atlassian arbitrary file access is CVE-2026-21589
Atlassian’s 5 October 2026 advisory for CVE-2026-21589 covers unauthenticated reads of known paths under the web root across Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible, and Fisheye Data Center lines. CVSS 4.0 9.3. Public detector exists. Not in CISA KEV. Atlassian has not confirmed Data Center exploitation in the advisory.
Published 3h ago
CriticalPoC Available
CVE-2026-21589
Atlassian Data Center unauthenticated arbitrary file access
Info disclosure
Published 2d ago