← nejvýznamnější zprávy · všechny zprávy

poslední zpráva · zachyceno

SPOJENO AI KEV ✓ (3 z 11) · ransomware EPSS 1.00 (nejvyšší)

Atlassian warns of critical file-access flaw in Jira, Confluence

Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket. [...]

Číst originál na BleepingComputer →

6 zpráv z 6 zdrojů · první · zachyceno CZ · EN/orig

Atlassian FI US NL CA IT FR

tg: zranitelnost

CVE v události 11

CVEhodnoceníKEVEPSS
CVE-2019-13990 9.8 3.1 · CISA-ADP – 0.16
CVE-2022-1471 8.3 3.1 · Google – 1.00
CVE-2022-23521 9.8 3.1 · GitHub_M – 0.56
CVE-2022-41903 9.8 3.1 · GitHub_M – 0.44
CVE-2023-22518 10.0 3.0 · atlassian KEV ✓ 1.00
CVE-2023-22522 9.0 3.0 · atlassian – 0.13
CVE-2023-22523 9.8 3.0 · atlassian – 0.11
CVE-2023-22524 9.6 3.0 · atlassian – 0.25
CVE-2023-22527 10.0 3.0 · atlassian KEV ✓ 1.00
CVE-2023-46604 10.0 3.1 · apache KEV ✓ 1.00
CVE-2026-21589 9.3 4.0 · atlassian – 0.01

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.3.

Jak se o tom psalo 6

  1. · zachyceno · NCSC-FI FI

    Atlassian: CVE-2026-21589 - Arbitrary File Access Vulnerability impacts Multiple Products

    Classification: Critical, Solution: Official Fix, Exploit Maturity: Proof-of-Concept, CVSSv4.0: 9.3, CVEs: CVE-2026-21589, Summary: All versions of Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye are affected by this vulnerability. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory…

  2. · BleepingComputer US nadpis události

    Atlassian warns of critical file-access flaw in Jira, Confluence

    Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket. [...]

  3. · NCSC-NL NL

    NCSC-2026-0402 [1.00] [M/H] Kwetsbaarheid verholpen in Atlassian Data Center producten

    De kwetsbaarheid bevindt zich in meerdere producten binnen het Atlassian Data Center-platform, waaronder Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo, Crowd, Crucible en Fisheye. De kwetsbaarheid betreft een Arbitrary File Access-probleem waarmee ongeauthenticeerde aanvallers specifieke bestanden binnen de rootdirectory van de webapplicatie kunnen benaderen. Exploitatie vereist kennis van het exacte bestandspad en de bestandsnaam. Hierdoor kunnen mogelijk gevoelige…

  4. · Cyber Centre Kanada CA

    Atlassian security advisory (AV26-1002)

    Serial number: AV26-1002 Date: October 5, 2026 As of October 5, 2026, Atlassian is affected by a vulnerability in the following products: Bamboo Data Center Version 10.2.4 and prior Version 12.1.12 and prior Bamboo Server All versions Bitbucket Data Center Version 10.2.8 and prior Version 10.5.1 and prior Version 9.4.26 and prior Bitbucket Server All versions Confluence Data Center Version 10.2.19 and prior Version 9.2.26 and prior Confluence Server All versions Crowd Data Center Version 6.3.7…

  5. · CSIRT Itálie (ACN) IT

    Risolta vulnerabilità in prodotti Atlassian

    Aggiornamenti di sicurezza risolvono una vulnerabilità con gravità "critica" in diversi prodotti Atlassian. Tale vulnerabilità, qualora sfruttata, potrebbe permettere a un utente malintenzionato non autenticato di accedere a specifici file (purché conosca in anticipo nome e percorso del file) situati nella cartella "root" dell'applicazione web interessata.

  6. · zachyceno · CERT-FR – avis FR

    Multiples vulnérabilités dans les produits Atlassian (06 octobre 2026)

    De multiples vulnérabilités ont été découvertes dans les produits Atlassian. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données.