Executive Summary
Atlassian has released urgent patches addressing multiple critical vulnerabilities impacting eight of its core products, including Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo, Crowd, and Fisheye/Crucible. These vulnerabilities, disclosed in the Atlassian Security Bulletin - August 18, 2026, include flaws that enable remote code execution (RCE), arbitrary file access, denial of service (DoS), and broken authentication. Several vulnerabilities are rated as critical, with CVSS scores up to 9.8. While there are credible reports of exploitation in the wild, the most severe arbitrary file access vulnerability (CVE-2026-21589) is not currently listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog, and there is no CISA-confirmed active exploitation. Organizations using affected versions are strongly urged to patch immediately and monitor for signs of compromise.
Technical Information
The vulnerabilities span both Atlassian-developed code and third-party dependencies. The most critical, CVE-2026-21589, allows unauthenticated attackers to access arbitrary files within the web root of affected applications, potentially exposing sensitive configuration or credential files. Exploitation requires knowledge of the exact file name and path, but the risk is amplified for externally accessible deployments.
Other high-impact vulnerabilities include:
CVE-2026-4800 (RCE via lodash in Jira Software Data Center), CVE-2023-45133 (RCE via @babel/traverse in Jira Software Data Center), CVE-2026-12143 (RCE via form-data in multiple products), and CVE-2026-14682 (RCE via org.bouncycastle:bcprov-jdk18on in Bamboo Data Center). These vulnerabilities allow attackers to execute arbitrary code on the server, potentially leading to full system compromise.
Denial of service vulnerabilities, such as CVE-2026-59873 (node-tar in Jira and Confluence) and CVE-2026-59874 (tar in Jira Service Management), can be exploited to disrupt service availability.
Broken authentication and session management (CVE-2026-21582) in Jira and Crowd Data Center may allow attackers to bypass authentication controls or escalate privileges.
Additional vulnerabilities affect dependencies like axios, org.hibernate, and org.postgresql, introducing risks of SQL injection, server-side request forgery (SSRF), and information disclosure.
The attack surface is broad, and exploitation techniques align with MITRE ATT&CK tactics such as T1190 (Exploit Public-Facing Application), T1059 (Command and Scripting Interpreter), T1071 (Application Layer Protocol), and T1005 (Data from Local System).
Exploitation in the Wild
Reports from Cybersecurity News indicate that some vulnerabilities, particularly those enabling arbitrary file access and RCE, have been exploited in the wild. However, CVE-2026-21589 is not listed in the CISA KEV catalog as of this writing, and there is no CISA-confirmed active exploitation. Atlassian’s own investigation has not found evidence of exploitation for this specific vulnerability. The lack of public proof-of-concept exploit code does not diminish the urgency, as the unauthenticated nature of the flaw makes it highly attractive to attackers, especially for internet-exposed instances.
APT Groups using this vulnerability
No specific advanced persistent threat (APT) groups have been publicly attributed to exploitation of these vulnerabilities at this time. However, the techniques enabled by these flaws are consistent with the tradecraft of groups such as APT41 and FIN11, which have previously targeted Atlassian and Confluence deployments. The vulnerabilities’ characteristics—unauthenticated access, RCE, and file disclosure—are commonly leveraged in initial access and lateral movement campaigns.
Affected Product Versions
The following Atlassian products and versions are affected:
Jira Software Data Center and Server: 11.3.0–11.3.8 (LTS), 10.3.0–10.3.23 (LTS), and additional versions as detailed in the official bulletin.
Jira Service Management Data Center and Server: 11.3.0–11.3.8 (LTS), 10.3.0–10.3.23 (LTS), and others.
Confluence Data Center and Server: 10.2.0–10.2.14 (LTS), 9.2.0–9.2.22 (LTS), and others.
Bitbucket Data Center and Server: 10.4.1, 10.2.0–10.2.5 (LTS), 9.4.0–9.4.22 (LTS), and others.
Bamboo Data Center and Server: 12.1.0–12.1.9 (LTS), 10.2.0–10.2.21 (LTS), and others.
Crowd Data Center and Server: 7.2.0–7.2.1, 6.3.0–6.3.6, and others.
Fisheye/Crucible: 4.9.0–4.9.12.
For a comprehensive list of affected and fixed versions, consult the Atlassian Security Bulletin.
Workaround and Mitigation
Immediate patching to the latest fixed versions is the most effective mitigation. If patching cannot be performed immediately, organizations should remove affected instances from public internet exposure. Temporary mitigations include deploying a web application firewall (WAF) or reverse proxy with Atlassian-supplied regular expressions to block traversal patterns, and using Tomcat’s RewriteValve with Atlassian-provided configuration. Administrators should monitor logs for unusual file access attempts, review user accounts for unauthorized changes, and ensure sensitive files are not stored in web-accessible directories. Isolate vulnerable systems if patching is delayed.
Indicators of Compromise
The following caveat applies: Indicators of compromise are point-in-time and should be validated before enforcement. No public indicators of compromise were available at the time of writing.
References
Atlassian Security Bulletin - August 18, 2026, SiteGuarding Blog, Cybersecurity News, Australian Cyber Security Centre.
Rescana is here for you
Rescana provides a comprehensive third-party risk management (TPRM) platform, empowering organizations to continuously monitor, assess, and mitigate cyber risks across their vendor ecosystem. Our platform leverages advanced automation and threat intelligence to deliver actionable insights and help you stay ahead of emerging threats. We are happy to answer any questions at info@rescana.com.



