Atlassian patches critical file-access flaw in Jira, Confluence and other Data Center products
CVE-2026-21589 lets an unauthenticated attacker read specific files from the web root of self-hosted Atlassian products. Fixed versions are out, cloud customers are already covered, and Atlassian says it has no evidence of exploitation so far.
Sources: 33 min read