Atlassian Patches Critical Vulnerabilities in Jira, Confluence, Bitbucket, and Five More Products
Atlassian has disclosed a critical arbitrary file access vulnerability affecting eight products, including Jira, Confluence, and Bitbucket. Tracked as CVE-2026-21589, the flaw has a CVSS score of 9.3. It lets unauthenticated attackers access specific files in an affected application’s web root...