Attackers Target Critical Atlassian Data Center Flaw Within Two Hours of Technical Details Going Public
Attackers have begun exploiting a newly disclosed critical flaw in Atlassian Data Center products. Tracked as CVE-2026-21589 and rated 9.3 out of 10 for severity, it affects Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible and Fisheye. Atlassian says an unauthenticated attacker can access specific files within the web application root directory. Atlassian Cloud products have already been patched, and fixes are available for the affected Data Center products.
There are limits to the flaw. Atlassian says an attacker must already know the exact name and path of the target file, and the flaw does not let them list directory contents. However, some configurations may hold sensitive files that raise the risk. Researchers at watchTowr said the flaw can be used to retrieve tokens, credentials, keys or other authentication material through a single request. Security firm Previdian reported 15 exploitation attempts against its honeypot network from three IP addresses in Japan and the U.S. The activity began about two hours after watchTowr published additional technical details.
For organisations that cannot patch immediately, Atlassian recommends temporary steps: remove the instance from the public internet, apply a Web Application Firewall rule, and block requests using Tomcat's RewriteValve for Confluence, Jira Service Management, Jira, Bamboo and Crowd. Bitbucket customers should add a new rule to urlrewrite.xml.