News with an accent.

Two-story office building with a white Atlassian sign on a black wall and a glass tower behind it.
Privacy

Attacks on Atlassian flaw reported after public write-up

Security firm Previdian says attempts began about two hours after watchTowr published its analysis. Atlassian has not confirmed them, and a patch has existed since Oct. 5.

Security firm Previdian says it has detected attempted attacks on CVE-2026-21589, the critical flaw in Jira, Confluence and Bitbucket that Atlassian fixed on Oct. 5, according to BleepingComputer. The attempts began about two hours after watchTowr Labs published a technical report on the defect, along with a detection tool, on Oct. 6.

The warning does not come from Atlassian. In its security advisory, the company says it found no evidence of exploitation in its cloud and that, for customers' own installations, it cannot tell whether any were affected. Previdian saw the activity on a network of honeypots, decoy servers left exposed to record who attacks them. No authority has confirmed that exploitation.

The flaw lets an attacker with no account reach files on the server. It affects the Data Center editions of Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo and Crowd, plus Crucible and Fisheye. The fixed versions, such as Confluence 9.2.26 and 10.2.19, are listed in the advisory and in our Oct. 7 story.

What is new is the speed. BleepingComputer reports that a template for Nuclei, an automated scanner, is already circulating, which makes it easier to hunt for servers that have not been updated. This newsroom does not describe how the flaw is exploited, and it is not confirmed whether watchTowr's report includes complete attack code or only the detection tool.

Organizations install Data Center editions on their own servers, so each IT team has to apply the patch itself. Both Atlassian and watchTowr say a web application firewall rule is a stopgap and no substitute for the patch. watchTowr also warns that a Crowd configuration file can hold credentials in plain text, which in some installations would open the identity system and connected applications, and it recommends rotating credentials if exposure is suspected.

Still unknown is whether the U.S. agency CISA adds the flaw to its catalog of exploited vulnerabilities, and how many installations remain unpatched.

Keep reading

El Mediático uses cookies to measure its audience and, where advertising is active, to show ads. You can accept all, reject all, or choose what to allow. The cookie policy is available in Spanish only. More about cookies (Spanish)