Attackers began probing the Atlassian Data Center flaw CVE-2026-21589 within two hours of watchTowr publishing technical details on October 7, and watchTowr has confirmed in-the-wild activity against the vulnerability.
The flaw is an unauthenticated arbitrary file access bug rated CVSS 9.3. Atlassian published its advisory on October 6, and this report covers the exploitation that followed.
Exploitation Attempts Began Within Two Hours
Security firm Previdian observed 15 exploitation attempts from three IP addresses located in Japan and the United States. watchTowr confirmed the in-the-wild activity and said most of it consisted of fingerprinting and reconnaissance, in which attackers check which servers are vulnerable.
The speed is the notable fact. The first attempts followed publication of watchTowr’s technical write-up by roughly two hours, leaving little time between public details and attacker activity.
What the Attempts Look Like
The observed traffic is mostly reconnaissance. Neither firm reports data theft or later-stage compromise in the material available. Reconnaissance of this kind commonly precedes more targeted attacks against servers found to be vulnerable.
How the File Access Works
According to the technical details, the flaw lies in the web application root. A path-resolution trick turns strings such as “..::..::WEB-INF::web.xml” into directory traversal. An attacker can use it to read files that should not be reachable.
Files and Credentials at Risk
Files that could be exposed include crowd.properties, which holds credentials. Access to such a file would give an attacker credentials for the affected system.
Affected Products and Fixed Versions
The affected Data Center products are Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo and Crowd. Crucible and Fisheye are also affected.
Fixed versions include Bitbucket 9.4.26, 10.2.8 and 10.5.1, and Confluence 9.2.26 and 10.2.19. Fixes for the other products are listed in Atlassian’s advisory.
Patch Window Has Closed for Unpatched Servers
With details public and attacks under way, the patch window has effectively closed for Data Center servers that remain unpatched. Servers that are reachable from the internet and still run an affected version are the ones attackers can already fingerprint.
The Data Center products named in the advisory, Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo and Crowd, are affected by the flaw in the web application root, and Crucible and Fisheye are also listed. The number of exploitation attempts Previdian recorded, 15 from three IP addresses, is small in absolute terms, but it was recorded very soon after the technical details became public.
Context of the Disclosure Sequence
The sequence was short. Atlassian released its advisory and patches on October 6. watchTowr followed on October 7 with technical details, and attempts began within two hours of that publication. The gap between a vendor patch and public technical details is the period in which administrators can update before exploit methods circulate, and here the following attacker activity arrived almost immediately.
Previdian and watchTowr both contributed to the picture of the activity. Previdian counted the 15 attempts and the three source IP addresses in Japan and the United States, and watchTowr, whose write-up preceded the attempts, confirmed the activity as in-the-wild. The fixed Bitbucket releases are 9.4.26, 10.2.8 and 10.5.1, and the fixed Confluence releases are 9.2.26 and 10.2.19.
Atlassian products are used to manage source code, documentation, tickets and identity, so a flaw that exposes files containing credentials affects systems that connect to many others. The reconnaissance observed so far does not show what, if anything, attackers have retrieved from the servers they probed.
The response from Atlassian and the researchers is to upgrade immediately. Organizations running any of the affected Data Center products can compare their installed versions against the fixed releases to establish whether they remain exposed.
