Atlassian Issues Critical Advisory for Arbitrary File-Access Vulnerability in Data Center Products
CVE-2026-21589 affects Confluence, Jira, and Bitbucket self-hosted deployments

Key Takeaways
- Atlassian has disclosed CVE-2026-21589, a critical arbitrary file-access vulnerability.
- Affected products: Confluence, Jira, and Bitbucket Data Center editions.
- The flaw was disclosed on October 6, 2026.
- Atlassian has released security updates; immediate patching is recommended.
- No confirmed reports of active exploitation were provided in the advisory, but the risk is assessed as critical.
Related Security News
Critical Remote Code Execution Vulnerability in Hitachi Energy SOI
Hitachi Energy has disclosed a high-severity Remote Code Execution vulnerability in the Apache ActiveMQ component of its SOI product. The flaw, tracked as CVE-2026-34197, stems from improper control of code generation in the Jolokia JMX-HTTP bridge. An authenticated attacker can exploit the default access policy to execute arbitrary code on the broker's JVM, potentially compromising confidentiality, integrity, and availability. The vulnerability affects SOI versions 2.0.0 through 2.2.0 and has been assigned a CVSS v3 base score of 8.8 (HIGH).



