Attackers Exploit Critical Atlassian Data Center Flaw CVE-2026-21589 Hours After PoC Release
Exploitation attempts against the critical vulnerability CVE-2026-21589 in Atlassian Data Center products began within hours of a public proof-of-concept release. The flaw permits unauthenticated reading of specific files and, in environments integrated with Crowd, can lead to privilege escalation up to administrator rights.
The defect affects a wide range of Atlassian Data Center deployments, including Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. It received a CVSS v4.0 score of 9.3 from Atlassian. The availability of a Nuclei template has lowered the barrier for large-scale automated scanning.
The vulnerability does not allow directory enumeration. Attackers must already know the exact file name and path. It exploits how a shared web resource library converts double-colon sequences into path separators, enabling path traversal requests against plugin resource endpoints.
The most severe scenario occurs when Jira is integrated with Crowd. Reading WEB-INF/classes/crowd.properties can expose plaintext credentials in certain configurations, allowing an attacker to create accounts and gain administrator privileges through the Crowd API.
Atlassian recommends applying fixed versions immediately, removing affected instances from the internet, or restricting external access. Additional mitigations include deploying WAF rules or enabling Tomcat RewriteValve with rewrite rules to block traversal patterns in Confluence, Jira, Jira Service Management, Bamboo, and Crowd. For Bitbucket Data Center the equivalent configuration is applied in urlrewrite.xml.
Administrators hunting for prior activity should examine access logs after double URL decoding and search for sequences containing .. combined with /, \, or ::, or apply the vendor-supplied search expression. If logs show access to sensitive configuration files, organizations must rotate credentials, strengthen network controls, and consider IP allow-listing in Crowd.
Related articles
LibreOffice and Apache OpenOffice Flaw Enables Remote Code Execution via Malicious Calc Tables Without Macro Warnings
Researchers have demonstrated an attack against LibreOffice and Apache OpenOffice users that executes arbitrary Java code simply by opening a malicious spreadsheet, without requiring macro permissions or triggering any security prompts. The vulnerability requires Java support to be enabled in the office suite and exploits legitimate features in the Calc component that automatically fetch data from external database sources. When a crafted document is opened, Calc loads a linked database file that references a malicious Java driver, allowing the attacker’s code to run inside the office process. LibreOffice has already patched the issue tracked as CVE-2026-63277 with the release of versions 26.2.5 and 26.8.0 on October 5, while Apache OpenOffice remains vulnerable up to version 4.1.16 under CVE-2026-59265 with a fix expected in 4.1.17. The attack chain works on both Windows and Linux and bypasses macro protections entirely because no user consent dialog appears. Although only a proof-of-concept exploit that launches the calculator has been published so far, the same technique can execute any Java payload. Users of OpenOffice are advised to disable Java or avoid untrusted files until the patch is available.
Atlassian Fixes Critical Path Traversal Flaw CVE-2026-21589 Exposing Files in Jira and Confluence
Atlassian has patched CVE-2026-21589, a CVSS 9.3 path traversal vulnerability that allows unauthenticated attackers to read files across eight products including Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye in Data Center editions. The flaw accepts manipulated paths where traversal sequences appear adjacent to forward slashes, backslashes or double colons, including URL-encoded variants. Attackers must know the exact file name and path because the vulnerability does not permit directory listing and is restricted to the web application root directory of each product. Configuration files located in predictable locations remain accessible to attackers familiar with the products. Patches have been released in specific versions such as Bitbucket 10.5.1, Confluence 10.2.19, Jira Software and Jira Service Management 11.3.12, Bamboo 12.1.12, Crowd 7.2.4 and Crucible and Fisheye 4.9.15. Atlassian found no evidence of exploitation in its cloud products, though the advisory does not address on-premises customer installations.
Apache Struts CVE-2026-104711 Enables Remote Code Execution via Legacy RESTful Mapper
Apache Struts has patched four vulnerabilities, one of which permits unauthenticated remote code execution through an OGNL injection flaw. The issue, tracked as CVE-2026-104711, only affects applications that still rely on the legacy RESTful mapper; modern configurations using the default mapper, restful2, or the official Struts REST plugin remain unaffected. Exploitation occurs when the legacy mapper extracts action names and parameters directly from the URL, allowing attackers to inject malicious OGNL expressions. Vulnerable releases span 2.0.0–2.3.37, 2.5.0–2.5.33, 6.0.0–6.11.0, and 7.0.0–7.3.0, with fixes available in 6.12.0 and 7.4.0. The remaining three flaws impact availability or cause cross-request data leakage but do not lead to code execution, and only one received an “important” severity rating.
Automated Pentesting and BAS: How AI Systems Like XBOW Outpace Human Researchers in Vulnerability Discovery
The article explores how automated penetration testing and Breach and Attack Simulation tools have evolved to provide continuous validation of security controls beyond annual manual pentests. It explains the distinction between BAS, which tests individual attack techniques against security tools using frameworks like MITRE ATT&CK, and autopentest solutions that build complete attack paths to critical assets. Russian vendor Positive Technologies released PT Dephaze 3.0 in October 2025, incorporating machine learning for controlled internal pentesting and earning the National Runet Award. Globally, AI-driven systems demonstrated superior performance, with XBOW topping HackerOne rankings by discovering over 1,000 vulnerabilities including 54 critical ones in just 90 days. Google’s Big Sleep project, combining DeepMind and Project Zero, identified and helped patch CVE-2025-6965 in SQLite before widespread exploitation. These developments underscore the need to integrate automated validation into vulnerability management processes under the emerging CTEM framework.