zero-day • BleepingComputer

Hackers Exploit Critical Atlassian CVE-2026-21589 Hours After Public PoC

A critical vulnerability across multiple Atlassian products, CVE-2026-21589, is now being exploited in unauthenticated attacks. Security firm Previdian saw exploitation attempts hit its honeypot network within two hours of watchTowr publishing a technical write-up and public proof-of-concept (PoC).

Hackers Exploit Critical Atlassian CVE-2026-21589 Hours After Public PoC

A critical vulnerability across multiple Atlassian products, CVE-2026-21589, is now being exploited in unauthenticated attacks. Security firm Previdian saw exploitation attempts hit its honeypot network within two hours of watchTowr publishing a technical write-up and public proof-of-concept (PoC). The issue is arbitrary file access in the application web root: an unauthenticated attacker who knows the exact file name and path can read protected files. Atlassian published advisories on Monday 5 October 2026; active scanning and exploit traffic were confirmed on 7 October.

Affected are self-hosted Data Center/server deployments of Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye. Atlassian Cloud is out of scope here. The root cause is a shared web-resource library that converts double colons `::` into forward slashes `/`, allowing directory-traversal requests through plugin resource endpoints inside the Tomcat application context. watchTowr confirmed file reads in Jira, Confluence and Bitbucket but could not leave the Tomcat context.

In Crowd-integrated Jira environments the chain can escalate sharply. If Crowd is reachable and the application has sufficient permissions, attackers can read plaintext application credentials from `WEB-INF/classes/crowd.properties` and create a Jira administrator account via Crowd’s API — controlling centralised identity, SSO and permissions. Restricting Crowd to an allow-list of IPs makes exploitation much harder; without that, attackers may need to pivot or abuse SSRF-like capabilities in Jira/Confluence/Bitbucket to reach Crowd.

Previdian has observed attempts from addresses including 38.60.157.86, 146.70.187.234 and 159.26.119.225 and recommends blocking them. A Nuclei template is already available, lowering the bar for mass scanning. watchTowr also released a free scanner to check whether instances are vulnerable. Atlassian cannot determine whether individual customer instances were already compromised — so patching and log hunting are immediate tasks, not “next maintenance window”.

For Nordic organisations running Jira/Confluence internally or internet-facing, the risk is concrete: collaboration platforms hold source, tickets, customer data and often API keys. Unauthenticated file read leading to Crowd admin is a classic zero-day-to-full-control path once a PoC is public. Even if Atlassian knew the bug before the patch, the operational reality now is active exploitation.

Many Nordic municipalities, healthcare providers, industrials and software firms still run self-hosted Jira Data Center behind VPN — or open to suppliers on the internet. That makes scanning for CVE-2026-21589 a low-effort campaign: a Nuclei template plus three known IPs are already circulating. Waiting for the “next quarterly window” risks both data exfiltration and persistent admin accounts created via Crowd. Incident response should assume worst case as soon as suspicious `::` calls appear in access logs.

Historically, Atlassian flaws such as Confluence OGNL and Jira auth bypasses were mass-exploited within days of a PoC. This time the file-read itself can look “limited” — until Crowd properties are read. That is why the advisory mitigations (WAF, RewriteValve, IP allow-lists) must be treated as temporary controls, not a substitute for patching. Organisations that already patched should still hunt IOCs: new admin users, changed group mappings and unusual Crowd API calls.

What IT and security leads should do now

Install Atlassian’s security updates for all affected Data Center products immediately. Restrict external access, add WAF/proxy rules against traversal patterns, and for Confluence/Jira/Bamboo/Crowd apply Tomcat RewriteValve rules per advisories; for Bitbucket use URL rewrite. Review logs for suspicious plugin-resource calls with `::`, new Crowd/Jira admin accounts and unusual WEB-INF reads. Treat signs of exploitation as full compromise of a Crowd-integrated chain: rotate secrets and audit users and permissions. Run watchTowr’s scanner against staging and production, and document which versions are in service before and after upgrade.

Sources & References

← All News Tools