Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Did Megan Rapinoe call for Jason Kelce’s firing?

    October 8, 2026

    Search warrants for former prince Andrew’s homes were unlawful, UK court rules

    October 8, 2026

    Former Labour MP cleared over role in fraudulent Covid-19 testing company | Coronavirus

    October 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Did Megan Rapinoe call for Jason Kelce’s firing?
    • Search warrants for former prince Andrew’s homes were unlawful, UK court rules
    • Former Labour MP cleared over role in fraudulent Covid-19 testing company | Coronavirus
    • Meeting of 9-10 September 2026
    • A year with Alexa Plus: The AI-powered assistant is better at running my home, but it’s not ready to run my life
    • Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication
    • Citi predicts Bitcoin going back to $113,000. Here’s what the buying data shows
    • To Block Solar Energy Projects, One Community Lumped Them in With Junkyards and Adult Bookstores
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, October 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 8, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Threat actors have started targeting CVE-2026-21589, a critical vulnerability in Atlassian’s self-hosted Data Center products. The attacks began shortly after technical details went public.

    Atlassian disclosed the bug on October 5 and gave it a CVSS score of 9.3. It affects Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye. Patches have been released for all affected versions.

    The flaw lets remote, unauthenticated attackers access specific files in the web application’s root directory. “Exploitation requires prior knowledge of the target file’s exact name and path,” Atlassian notes, adding that the vulnerability can’t be used to list directory contents.

    WatchTowr published its analysis on October 6. The researchers traced the issue to a library that the affected products share. 

    According to WatchTowr, the bigger risk shows up when Jira is integrated with Crowd, Atlassian’s identity management product. In that setup, an attacker can read a configuration file that stores Crowd application credentials in plaintext.

    WatchTowr used those credentials to create a new user and add it to the Jira administrators group. The researchers described direct Crowd access with leaked credentials as “basically game over.” 

    Advertisement. Scroll to continue reading.

    Exploitation intelligence firm Previdian says its honeypots began recording CVE-2026-21589 exploitation attempts on October 6, hours after WatchTowr’s findings went public. As of October 8, Previdian had logged 190 attempts from 32 IP addresses in 10 countries.

    CISA has not yet added CVE-2026-21589 to its Known Exploited Vulnerabilities catalog.

    Organizations are advised to update to the fixed versions. If they can’t patch right away, they should cut the instances off from the internet or apply the firewall and rewrite rules Atlassian provided.

    Related: TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws

    Related: FortiBleed Attackers Locking Victims Out of Fortinet Devices

    Related: SonicWall and Splunk Patch Critical Vulnerabilities

    Atlassian Attackers critical hours PoC Publication Target Vulnerability
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    US Seeks Alleged Chinese Hafnium Hacker With $10 Million Reward

    Rein Security Raises $25 Million to Guard AI Agents at Runtime

    TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws

    Fake Decryption Tools Masked $11M Markup in Ransomware Recovery Scheme

    We are fighting phishing at the wrong layer

    FortiBleed Attackers Locking Victims Out of Fortinet Devices

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Did Megan Rapinoe call for Jason Kelce’s firing?

    October 8, 2026

    Search warrants for former prince Andrew’s homes were unlawful, UK court rules

    October 8, 2026

    Former Labour MP cleared over role in fraudulent Covid-19 testing company | Coronavirus

    October 8, 2026

    Meeting of 9-10 September 2026

    October 8, 2026
    Latest Posts

    Wisconsin’s partisan primary election is Tuesday. Learn more about who’s on your ballot.

    August 10, 2026

    Gabon ends fisheries partnership agreement with EU

    August 10, 2026

    Science backs calls for limiting screens in schools

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Did Megan Rapinoe call for Jason Kelce’s firing?

    October 8, 2026

    Search warrants for former prince Andrew’s homes were unlawful, UK court rules

    October 8, 2026

    Former Labour MP cleared over role in fraudulent Covid-19 testing company | Coronavirus

    October 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.