LIVE · cybersecurity feed
Live wire
CVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-DayClingSTUN Malware Turns IoT Devices Into Proxy NodesCVE-2026-61500 · Rejetto HFS servers now actively scanned for critical RCE flawCVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
CVE-2026-21589critical

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

A critical vulnerability has been reported in eight Atlassian Data Center products, enabling unauthenticated attackers to read known files within the web application root directory. The flaw, identified as CVE-2026-21589, was disclosed by Atlassian on October 5th and carries a CVSS rating of 9.3 out of 10, indicating its severe impact and ease of exploitation.

ZeroDay News ·

Source: The Hacker News

Photo: Sardaka (CC0) via Wikimedia Commons

A critical vulnerability has been reported in eight Atlassian Data Center products, enabling unauthenticated attackers to read known files within the web application root directory. The flaw, identified as CVE-2026-21589, was disclosed by Atlassian on October 5th and carries a CVSS rating of 9.3 out of 10, indicating its severe impact and ease of exploitation.

The vulnerability specifically affects Atlassian Data Center products, which are self-hosted by customers. An attacker does not require any prior authentication or login credentials to exploit this flaw. The mechanism of the attack involves the attacker requesting a specific file by its exact name and path. While the attacker can read these known files, they are unable to list the contents of the directory, meaning they cannot discover file names or paths that are not already known to them.

This class of vulnerability, often related to path traversal or improper access control, typically arises when web servers or applications fail to adequately restrict access to files outside of intended public directories. In this instance, the web application appears to be serving files from its root directory without sufficient authorization checks. The impact of such a flaw can vary depending on the nature of the files exposed, but even configuration files, log files, or other application-specific data could contain sensitive information.

Mitigation for such issues generally involves applying vendor-provided patches promptly. For self-hosted products like Atlassian Data Center, customers are responsible for deploying these updates. In the absence of a patch, temporary mitigations might include implementing web application firewall (WAF) rules to block requests for known sensitive file paths or restricting access to the web application from untrusted networks. Secure configuration practices, such as ensuring least privilege for file access and regularly auditing web server configurations, are also crucial.

The affected products are all part of the Atlassian Data Center suite, which is designed for enterprise-level deployments requiring high availability and performance. These products commonly include collaboration, project management, and code management tools. The fact that the vulnerability affects eight different products underscores a potential common architectural or code base issue across the Data Center offerings.

The critical rating of 9.3 highlights the potential for significant compromise, given that no authentication is required and the flaw allows for direct file access. While the attacker needs to know the exact file name and path, this information can sometimes be inferred from publicly available documentation, error messages, or previous breaches.

This incident serves as a reminder of the ongoing challenges in securing complex web applications, particularly those deployed in self-hosted environments where the responsibility for patching and configuration often falls to the customer. Prompt application of security updates and adherence to secure configuration guidelines remain paramount in defending against such critical vulnerabilities.

vulnerabilities in this storyCVE-2026-21589
vulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-86360critical

Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root Access

Dell has issued an urgent advisory to customers, recommending they patch a critical vulnerability in its System Update (DSU) tool that could allow attackers to gain root access on affected PowerEdge servers. The flaw, identified as CVE-2026-86360, carries a CVSS score of 9.6, indicating its severe potential impact.

CVE-2026-88779high

Citrix NetScaler Hit by Third Actively Exploited Zero-Day

Citrix has disclosed a third actively exploited zero-day vulnerability affecting its NetScaler products, identified as CVE-2026-88779. This latest flaw, a denial-of-service vulnerability, specifically impacts NetScaler instances where Security Assertion Markup Language (SAML) is enabled. While inconvenient, security researchers generally consider its impact to be lower compared to the two…

breach

FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

The U.S. Federal Bureau of Investigation (FBI) has reportedly removed an Accenture contractor following an alleged security failure that contributed to a data breach attributed to the ShinyHunters threat group. This incident is said to have resulted in the theft of personal details belonging to thousands of FBI employees. The reported cause of the breach was a patch failure.

malware

ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure

Fortinet's FortiGuard Labs has detailed a new Linux backdoor, dubbed ClingSTUN, which leverages legitimate public Session Traversal Utilities for NAT (STUN) infrastructure to mask its command and control (C2) communications. The malware primarily targets unpatched Internet of Things (IoT) devices, functioning as a back-connect proxy that turns compromised systems into remotely controlled nodes.

ai

U.S. Bank CISO says the security role keeps growing and no one can own all of it

The role of a Chief Information Security Officer (CISO) has expanded significantly to encompass areas such as fraud, resilience, third-party risk, and AI governance, according to Ann Barron-DiCamillo, EVP and CISO at U.S. Bank. She notes that while this consolidation can make security leaders more effective by addressing interconnected risks, no single individual can realistically own every…

nation-state

Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account

Denmark's digitalization ministry has reported that unauthorized parties accessed the Central Person Register (CPR), the national population register, compromising data for approximately 8.8 million individuals. The accessed information includes names, addresses, and personal identification numbers. This incident, reported on October 5, affects both living and deceased persons registered in…