Threat actors have started exploiting a recently disclosed security flaw in Atlassian Data Center products that could allow unauthenticated attackers to access sensitive files.
The vulnerability, tracked as CVE-2026-21589, affects several Atlassian products, including Bitbucket, Confluence, Jira, Bamboo, Crowd, Crucible, and Fisheye. The flaw can allow attackers to retrieve specific files from an application's webroot directory if they know the exact file name and path. The files could contain credentials, tokens, encryption keys, or other sensitive information.
Security company Previdian said it detected 15 exploitation attempts from three IP addresses in Japan and the United States. The attacks began about two hours after technical details of the vulnerability were made public.
Atlassian has released security updates for the affected products and said its Cloud products have already been patched. The company is also advising customers to remove vulnerable systems from the public internet, use Web Application Firewall (WAF) rules, and apply other temporary protections until updates can be installed.
Customers using affected Data Center products are strongly advised to install the security fixes as soon as possible.