At least some attackers are attempting to exploit a newly disclosed critical security flaw in Atlassian self-managed Data Center products. The vulnerability, CVE-2026-21589, is described as an “arbitrary file access” issue that can allow an attacker to read sensitive files from a web application’s directory without authentication, depending on conditions.

Atlassian published patches for multiple affected products after the flaw was disclosed, urging customers to patch immediately. Multiple outlets report the problem affects several Data Center families, including Jira, Confluence, Bitbucket, and related products such as Bamboo, Crowd, and others. Help Net Security and The Hacker News add that exploitation attempts show up rapidly after public technical details, with threat-intelligence providers observing activity aimed at the flaw and sharing indicators such as attacker IPs. Bleeping Computer similarly reports exploitation following public proof-of-concept release, emphasizing attacks that do not require authentication.