Skip to content
Wednesday, 7 October 2026
Tenesys AI News
Subscribe

Cyber Security

Vulnerabilities, threats and incidents, security advisories from CERT-EU, ENISA, CISA and NCSC, AI security and regulation (NIS2, CRA).

#CVSS 9.3 — 1 article ✕

Critical Unauthenticated File Access Flaw Hits Multiple Atlassian Data Center Products

Atlassian disclosed CVE-2026-21589, a critical (CVSS 9.3) arbitrary file access vulnerability affecting Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd Data Center, Crucible and Fisheye. An unauthenticated attacker who knows a file's exact name and path can access it within the web application root, though directory listing is not possible. CERT-EU urges immediate patching, starting with internet-facing instances, and checking access logs for exploitation signs. Atlassian Cloud products are already patched, and no exploitation has been found so far.

CERT-EU