Hello,
Atlassian has discovered a critical vulnerability (CVE-2026-21589) impacting most Data Center products, listed below. This vulnerability carries a CVSS score of 9.3 and affects all versions of the impacted products.
If you are using any of the affected Data Center Products you must take immediate action to protect your instance. More information, including patching instructions and threat detection guidance, is available in the Critical Security Advisory.
CVE-2026-21589 - Arbitrary File Access Vulnerability
- Bitbucket Data Center
- Confluence Data Center
- Jira Service Management Data Center
- Jira Software Data Center
- Bamboo Data Center
- Crowd Data Center
- Crucible
- Fisheye
Affected Atlassian Cloud products have been patched, and our investigation has not found evidence of exploitation. No Cloud customer action is required.
If you have questions, please raise a support request via the instructions included in the advisory.