Exploitation attempts against critical Atlassian flaw have begun (CVE-2026-21589)

One day after Atlassian released patches fixing a critical arbitrary file access vulnerability (CVE-2026-21589) in its self-managed Data Center products, and a few hours after watchTowr researchers published a technical rundown of the flaw, attackers have been spotted attempting to exploit it…

cloudreleasessciencesecurity

Sources

Vulnerabilities

Why this score
Signals contributing to the severity score
SignalPoints
cvss critical — 9.320
widely deployed15
Exploitation attempts against critical Atlassian flaw have begun (CVE-2026-21589) · TechNews