Critical Jira, Confluence and Bitbucket Flaw Is Already Being Exploited: What to Do Today If You Self-Host Them

If your team runs Jira, Confluence or Bitbucket on its own server (in the office, in a datacenter or on a cloud virtual machine), today is the day to update. On Monday, October 5, 2026, Atlassian published security advisory CVE-2026-21589, a critical (9.3 out of 10) flaw that lets an attacker with no username or password read files from the server. By the next day there were already exploitation attempts, according to BleepingComputer and Help Net Security.
If you use Atlassian's cloud version (addresses ending in atlassian.net), you can relax: Atlassian says it has already patched its Cloud products, found no evidence of exploitation, and Cloud customers do not need to do anything.
What the flaw allows
According to the advisory, an unauthenticated attacker can read specific files within the web application's root directory. There is a limit: the attacker must know the exact file name and path, because they cannot list folders. The problem is that those paths are the same in every installation.
Security firm watchTowr published a technical analysis and, hours later, the honeypot network of the company Previdian began receiving exploitation attempts. Both BleepingComputer and Help Net Security explain the most serious risk: in installations with Crowd (Atlassian's user management product), the attacker can read the crowd.properties file, which stores application credentials in plain text, and use them to create administrator accounts. In other words, "reading a file" can turn into taking over Jira or Confluence, with all the tickets, internal documents and code they hold.
Affected products and fixed versions
All versions prior to the fixed ones of eight self-hosted products (Data Center and Server) are affected. These are the versions Atlassian published:
Jira Software Data Center9.12.40, 10.3.26, 11.3.12Jira Service Management Data Center5.12.40, 10.3.26, 11.3.12Confluence Data Center9.2.26, 10.2.19Bitbucket Data Center9.4.26, 10.2.8, 10.5.1Bamboo Data Center10.2.24, 12.1.12Crowd Data Center6.3.7, 7.0.3, 7.1.7, 7.2.4Crucible and Fisheye4.9.15If your version is older than the one for its branch, it is exposed. If your branch no longer gets a patch, you need to move to one of the branches in the table.
What to do today, in order
- Take inventory. Look for any Jira, Confluence, Bitbucket, Bamboo, Crowd, Crucible or Fisheye installed by your team or a vendor. The forgotten ones (an old project's Jira, a test Bitbucket) are the most dangerous.
- Update to the fixed version for your branch. It is Atlassian's main recommendation.
- If you cannot update today, take it off the internet. Atlassian recommends removing public access until patched: keep it on the internal network only or behind a VPN.
- Apply the temporary mitigation. The advisory offers three options: a web application firewall (WAF) rule blocking the
..sequence next to/,\or::; Tomcat's RewriteValve for Jira, Confluence, Jira Service Management, Bamboo and Crowd; or a rule inurlrewrite.xmlfor Bitbucket. It is an emergency patch, not a substitute for updating. - Review the access logs, before and after patching, looking for requests containing
..next to/,\or::, as Atlassian indicates. watchTowr also published a free script to check whether an instance is vulnerable. - If you find traces, rotate credentials. Start with Crowd's and the service accounts stored in configuration files, and check whether new administrators have appeared.
What it means for your business
Many companies and development teams in Ecuador keep Jira or Confluence on their own server out of habit, cost or data policies. This flaw is a reminder of the price of that decision: when a critical patch comes out, someone has to apply it within hours, not at next month's maintenance window. If no one is responsible for those servers, it is worth naming someone today, or evaluating whether the Cloud version, which Atlassian patches on its own, is a better fit.
For developers there is an extra lesson: the tool where your code and documentation live is as critical as the production system. An attacker who reaches Bitbucket or Confluence can find passwords, network diagrams and API keys.
How We Approach It at SimCodec
At SimCodec we manage servers, cloud and backups and software development for businesses. We help you inventory your self-hosted tools, apply patches and mitigations without stopping your team, review the logs and decide whether to stay on your own server or move to the cloud.
If you have Jira, Confluence or Bitbucket on your server and do not know which version it runs, write to us or call our AI assistant Cyntia at +593 99 726 6838.


