poslední zpráva · zachyceno
SPOJENO AI KEV ✓ (3 z 11) · ransomware EPSS 1.00 (nejvyšší)
Atlassian warns of critical file-access flaw in Jira, Confluence
Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket. [...]
Atlassian FI US NL CA IT FR
CVE v události 11
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2019-13990 | 9.8 3.1 · CISA-ADP | – | 0.16 |
| CVE-2022-1471 | 8.3 3.1 · Google | – | 1.00 |
| CVE-2022-23521 | 9.8 3.1 · GitHub_M | – | 0.56 |
| CVE-2022-41903 | 9.8 3.1 · GitHub_M | – | 0.44 |
| CVE-2023-22518 | 10.0 3.0 · atlassian | KEV ✓ | 1.00 |
| CVE-2023-22522 | 9.0 3.0 · atlassian | – | 0.13 |
| CVE-2023-22523 | 9.8 3.0 · atlassian | – | 0.11 |
| CVE-2023-22524 | 9.6 3.0 · atlassian | – | 0.25 |
| CVE-2023-22527 | 10.0 3.0 · atlassian | KEV ✓ | 1.00 |
| CVE-2023-46604 | 10.0 3.1 · apache | KEV ✓ | 1.00 |
| CVE-2026-21589 | 9.3 4.0 · atlassian | – | 0.01 |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.3.
Jak se o tom psalo 6
-
· zachyceno · NCSC-FI FI
Atlassian: CVE-2026-21589 - Arbitrary File Access Vulnerability impacts Multiple Products
Classification: Critical, Solution: Official Fix, Exploit Maturity: Proof-of-Concept, CVSSv4.0: 9.3, CVEs: CVE-2026-21589, Summary: All versions of Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye are affected by this vulnerability. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory…
-
· BleepingComputer US nadpis události
Atlassian warns of critical file-access flaw in Jira, Confluence
Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket. [...]
-
· NCSC-NL NL
NCSC-2026-0402 [1.00] [M/H] Kwetsbaarheid verholpen in Atlassian Data Center producten
De kwetsbaarheid bevindt zich in meerdere producten binnen het Atlassian Data Center-platform, waaronder Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo, Crowd, Crucible en Fisheye. De kwetsbaarheid betreft een Arbitrary File Access-probleem waarmee ongeauthenticeerde aanvallers specifieke bestanden binnen de rootdirectory van de webapplicatie kunnen benaderen. Exploitatie vereist kennis van het exacte bestandspad en de bestandsnaam. Hierdoor kunnen mogelijk gevoelige…
-
· Cyber Centre Kanada CA
Atlassian security advisory (AV26-1002)
Serial number: AV26-1002 Date: October 5, 2026 As of October 5, 2026, Atlassian is affected by a vulnerability in the following products: Bamboo Data Center Version 10.2.4 and prior Version 12.1.12 and prior Bamboo Server All versions Bitbucket Data Center Version 10.2.8 and prior Version 10.5.1 and prior Version 9.4.26 and prior Bitbucket Server All versions Confluence Data Center Version 10.2.19 and prior Version 9.2.26 and prior Confluence Server All versions Crowd Data Center Version 6.3.7…
-
· CSIRT Itálie (ACN) IT
Risolta vulnerabilità in prodotti Atlassian
Aggiornamenti di sicurezza risolvono una vulnerabilità con gravità "critica" in diversi prodotti Atlassian. Tale vulnerabilità, qualora sfruttata, potrebbe permettere a un utente malintenzionato non autenticato di accedere a specifici file (purché conosca in anticipo nome e percorso del file) situati nella cartella "root" dell'applicazione web interessata.
-
· zachyceno · CERT-FR – avis FR
Multiples vulnérabilités dans les produits Atlassian (06 octobre 2026)
De multiples vulnérabilités ont été découvertes dans les produits Atlassian. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données.