Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication
Attackers probed critical Atlassian CVE-2026-21589 within hours of a public PoC, with 190 honeypot attempts.
Atlassian disclosed CVE-2026-21589 on October 5, rating the self-hosted Data Center flaw CVSS 9.3 across Bitbucket, Confluence, Jira, Bamboo, Crowd, and related products. A remote unauthenticated attacker who knows an exact path can read files in the web root; WatchTowr showed that Crowd integration can expose plaintext credentials used to create a Jira administrator. Previdian honeypots recorded exploitation attempts starting October 6, reaching 190 attempts from 32 IP addresses by October 8. Patches are available, and CISA has not yet added the bug to the KEV catalog.