Atlassian patches a critical arbitrary file-access flaw spanning seven Data Center products
On 6 October 2026, Atlassian published CVE-2026-21589, a critical flaw that lets an unauthenticated attacker read specific files in the web root of Confluence, Jira, Bitbucket and four other self-hosted Data Center products. Cloud instances are already patched: only Data Center administrators need to patch or apply the documented mitigations, on every cluster node.