CVE-2026-21589critical
Exploitation attempts against critical Atlassian flaw have begun (CVE-2026-21589)
Exploitation attempts have begun against a critical arbitrary file access vulnerability, CVE-2026-21589, affecting multiple self-managed Atlassian Data Center products. The attempts were observed by threat intelligence vendor Previdian on Tuesday, just one day after Atlassian released patches and hours after security researchers published a technical analysis of the flaw.
vulnerabilitycritical
Atlassian Patches Critical Vulnerability Affecting 8 Products
Atlassian has released patches for a critical vulnerability impacting eight of its products. The flaw, if exploited, could allow unauthenticated attackers to gain access to specific files located within the web application's root directory. This type of access could potentially expose sensitive configuration or application data, depending on the contents of the accessible files.
CVE-2026-21589critical
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
A critical vulnerability has been reported in eight Atlassian Data Center products, enabling unauthenticated attackers to read known files within the web application root directory. The flaw, identified as CVE-2026-21589, was disclosed by Atlassian on October 5th and carries a CVSS rating of 9.3 out of 10, indicating its severe impact and ease of exploitation.
vulnerabilitycritical
Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities
Atlassian and Splunk have released patches addressing numerous critical and high-severity vulnerabilities across their product lines. The reported flaws could potentially be exploited by attackers to achieve arbitrary code execution, gain unauthorized access to sensitive data, and escalate privileges within affected systems. Users of Atlassian and Splunk products are strongly advised to apply…
vulnerability
Researchers Uncover RovoBlast Vulnerability in Atlassian AI Assistant
A vulnerability, dubbed "RovoBlast" by Varonis Threat Labs, was discovered in Atlassian's enterprise AI assistant, Rovo, allowing for the exfiltration of company data through a single crafted link. The flaw was disclosed to Atlassian by Varonis, which published its analysis on August 7 after presenting the research at DEF CON 34. Atlassian has since confirmed and fixed the issue.
breachcritical
Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data
A critical one-click vulnerability has been reported in Atlassian’s Rovo AI, which could have exposed enterprise data. The flaw, dubbed "RovoBlast" by researchers at Varonis, reportedly allowed for the exfiltration of sensitive information from linked Atlassian Confluence and Jira instances, as well as Microsoft SharePoint. The nature of a "one-click" vulnerability suggests a low barrier to…