Atlassian has issued fixes for CVE-2026-21589, a critical vulnerability affecting Jira Software Data Center and Confluence Data Center. The issue is described as unauthenticated access to specified files in affected web-root directories, with a reported CVSS score of 9.3.

The practical constraint matters: an attacker must know the target filename and path, and the published material says the flaw does not enable directory listing. That reduces discovery opportunities but does not remove risk where applications expose predictable or sensitive files.

Teams running affected Data Center deployments should identify exposed instances, apply the fixed releases supplied by Atlassian, and prioritize older or internet-facing systems. Atlassian lists fixes for Jira Data Center 9.12.40, 10.3.26 and 11.3.12, and for Confluence Data Center 9.2.26 and 10.2.19. Cloud customers were already patched, according to the vendor reporting.

Where patching cannot happen immediately, reduce external exposure and test compensating reverse-proxy or WAF controls. Those measures are temporary; update planning and verification remain the essential response.

Source: GBHackers; Atlassian Jira advisory; Atlassian Confluence advisory.

`

By Allan