BreachFeed
← All incidents
companyAtlassian
suspectedlowVulnerabilityFirst reported Oct 7, 2026

Atlassian: critical Data Center file access flaw exploited within hours of disclosure

A critical arbitrary file access vulnerability, CVE-2026-21589 (CVSS 9.3), affects multiple Atlassian Data Center products including Bitbucket, Confluence, and Jira Service Management and Software. Threat actors reportedly began exploitation attempts within two hours of public details being released.

Members only

The full record: the timeline and 1 linked report

  • Every update as it happened, with the status at each step
  • Every report behind the record, newest first
  • Alerts the moment Atlassian — or anything else you track — is hit again

A free account is all it takes — no card, one minute.