Hackers exploit Atlassian zero-day within two hours of public exploit code

Attackers began probing for CVE-2026-21589, a critical unauthenticated file-access flaw in self-hosted Atlassian software, within two hours of security firm watchTowr publishing a technical writeup and proof-of-concept exploit on Monday. Honeypot operator Previdian logged scanning attempts from three IP addresses — 38.60.157.86, 146.70.187.234, and 159.26.119.225 — almost as soon as the research went live.
The flaw sits in a shared library used across Atlassian's Data Center product line that converts the character sequence "::" into "/" when resolving file paths. An attacker who knows the exact path of a file can exploit that conversion to perform directory traversal and retrieve files from the web root without authenticating — a textbook case of a logic bug in shared code becoming a company-wide exposure. Affected products include Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian's cloud-hosted products are not affected; only self-hosted Data Center installations are at risk.
Jira and Confluence servers are a favorite target for attackers precisely because of what they store: internal design documents, credentials pasted into tickets, API keys, source-code links, and incident postmortems. A file-read bug that needs no login turns any internet-facing Data Center instance into an open filing cabinet for anyone who can guess or discover a few file paths. Within hours of the PoC's release, a Nuclei scanning template had already been published, letting any attacker — skilled or not — automate discovery of vulnerable servers at scale.
Atlassian has urged customers to apply the available patches immediately. For organizations that cannot patch right away, the company and researchers have suggested interim mitigations: web application firewall rules targeting the "::" path pattern, Tomcat RewriteValve configurations to block the traversal, and restricting network access to Data Center instances from the public internet. Ryan Dewhurst of Previdian, whose honeypot network caught the first exploitation attempts, said the speed of the attacks — live within two hours of a public PoC — reflects how quickly opportunistic scanning networks now operationalize disclosed vulnerabilities.
As first reported by BleepingComputer, any organization running an internet-facing, self-hosted Atlassian Data Center product should treat patching as urgent rather than routine maintenance.
Originally reported by BleepingComputer. Read the original article for additional details.
View original source