Cyber Threat Brief — October 6 2026
1. Atlassian Data Center unauth web-root file read — CVE-2026-21589
TL;DR: Atlassian disclosed CVE-2026-21589 on 2026-10-05 (CVSS 9.3): an unauthenticated attacker who already knows an exact file path can read that file from the web application root on eight self-hosted Data Center products. Cloud is patched with no exploitation found. Inventory every internet-facing Jira, Confluence, Bitbucket, Bamboo, Crowd, Crucible, and Fisheye node and move it to a fixed build before you lean on the WAF regex.
What’s New:
- One CVE covers Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye Data Center. Exploitation needs the exact name and path; directory listing is not part of the bug. Atlassian still rates impact High on confidentiality (and on other systems in the CVSS 4.0 vector).
- Fixed builds as of 2026-10-06 media and product tickets: Bitbucket 9.4.26 / 10.2.8 / 10.5.1; Confluence 9.2.26 / 10.2.19; Jira Software 9.12.40 / 10.3.26 / 11.3.12; JSM 5.12.40 / 10.3.26 / 11.3.12; Bamboo 10.2.24 / 12.1.12; Crowd 6.3.7 / 7.0.3 / 7.1.7 / 7.2.4; Crucible and Fisheye 4.9.15. Crowd’s 7.1 line is messy in the CVE record (7.1.1) versus the product ticket (7.1.7); take the ticket’s fixed list and confirm against your branch release notes before you close the change.
- Temporary bridge (not a patch): WAF/reverse-proxy regex that blocks
..immediately next to/,\, or::(including nested URL encoding). Confluence/Jira/JSM/Bamboo/Crowd can also use TomcatRewriteValve+rewrite.config; Bitbucket uses a matching rule at the top ofapp/WEB-INF/urlrewrite.xmlon every node and mirror. Crucible/Fisheye get the WAF option only. - Atlassian says Cloud is already patched and its investigation found no evidence of exploitation. Self-hosted exposure is on you: URL-decode access logs up to twice and hunt for
..beside/,\, or::, or replay the vendor block pattern over raw lines. PoC-in-GitHub and nuclei-templates had no CVE-2026-21589 entry at draft time.
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
| Self-hosted Atlassian Data Center builds below Bitbucket 9.4.26/10.2.8/10.5.1, Confluence 9.2.26/10.2.19, Jira Software 9.12.40/10.3.26/11.3.12, JSM 5.12.40/10.3.26/11.3.12, Bamboo 10.2.24/12.1.12, Crowd 6.3.7/7.0.3/7.1.7/7.2.4, Crucible/Fisheye 4.9.15 | Vulnerable app | T1190 | App admin → System info / CATALINA_HOME install inventory / CMDB | List every self-hosted node (including Bitbucket mirrors). If the running build is below the fixed line for that product branch, upgrade to the matching fixed build. Prefer a fixed LTS when you cannot jump to the newest train. |
Atlassian WAF/proxy regex blocking .. adjacent to /, \, or :: (nested %25 / %2e / %2f / %5c / %3a forms included) | Interim mitigation | T1190 | WAF / reverse proxy / load balancer policy | If you cannot upgrade today, deploy the vendor regex on the edge in front of every public Atlassian DC VIP. Test with encoded .. probes. Treat this as a bridge only. |
Tomcat RewriteValve + WEB-INF/rewrite.config (Confluence, Jira Software, JSM, Bamboo, Crowd) or Bitbucket app/WEB-INF/urlrewrite.xml rule returning 404 | Host mitigation | T1190 | conf/server.xml, product WEB-INF, Bitbucket urlrewrite.xml | On each cluster/mirror node, install the vendor rewrite rule, restart, and confirm a crafted ../ URL returns 404 before the app handles it. Do not skip mirrors. |
Access-log lines where URL-decoded path (up to two decode passes) shows .. next to /, \, or :: | Hunt / IR pivot | T1190 | Access logs / reverse proxy / WAF | Decode each request line up to twice and flag .. adjacent to /, \, or ::, or run Atlassian’s block pattern over raw lines. Preserve matching windows; upgrade first, then decide whether the hit returned a file. |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | None — verified | Confluence ESCU stories (CVE-2022-26134, CVE-2023-22515, CVE-2023-22527) match OGNL ${ / privilege-escalation paths, not .. web-root reads for CVE-2026-21589. |
| Elastic | None — verified | Local elastic_dr tree has no rule whose logic targets Atlassian web-root ../ reads for this CVE. |
| Sigma | None — verified | Path Traversal Exploitation Attempts only matches hard-coded ../../../etc/ / Windows / double-encoded etc strings. Emerging-threat Confluence/Bitbucket rules cover older CVEs (2019–2023). None name CVE-2026-21589. |
Hunt hint: Pull version from every internet-reachable Atlassian DC VIP today. If any node sits below the fixed line for its branch, either upgrade or take it off the public internet and apply the WAF/rewrite bridge. Then sweep seven days of access logs with Atlassian’s double-decode .. hunt. A hit is a lead for IR, not automatic proof a sensitive file left the box — Atlassian does not publish which filenames matter in which configs.
Sources: The Hacker News · CONFSERVER-104488 · JSDSERVER-16809 · BSERV-20604 · JRASERVER-79546 · OpenCVE CVE-2026-21589
Status Updates
- CVE-2026-88779 (NetScaler): CISA KEV due TOMORROW 2026-10-07; forensic triage Yes. Still vendor/KEV DoS on SAML SP/IdP. Fixed builds 14.1-73.41 / 13.1-64.28 / FIPS 14.1-73.41 / NDcPP 13.1-37.282. No new KEV add overnight (catalog still 2026.10.04, count 1734). Oct 5 brief.
- CVE-2026-104286 (FortiMail): KEV due was 2026-10-04; forensic triage Yes. Singapore CSA restated active exploitation on 2026-10-06. Previdian sensors reported probe volume into 2026-10-06 (X post cites POST /api/v1/ibe/import with multipart
../fields — treat as sensor-attributed, not a Fortinet FG-IR path). Keep IBE disable / management ACL,/data/etc/ld.so.preload, andliblog.sohunts; SecPod still framed fixed builds as upcoming (8.0.2, 7.6.7, 7.4.9). Oct 2 brief. - CVE-2026-102489 (Zammad): KEV due was 2026-10-05; forensic triage Yes. Confirm interim 7.2.0 and DIVD IOC script. Oct 3 brief.
- CVE-2026-102490 (Zammad): KEV due was 2026-10-05; forensic triage Yes. Local
zammadto root; no confirmed fixed build beyond leaving the affected line. Oct 3 brief. - CVE-2026-61500 (Rejetto HFS): Media wave (SecurityWeek / BleepingComputer 2026-10-05) restates VulnCheck canaries; still not CISA KEV. Keep 3.0.0–3.2.0 → ≥3.2.1,
/~/api/loginSrp1,server_code, and 173.239.211.248/249. Oct 4 brief. - CVE-2026-88062 (OmniRoute): No material change. Version line still disputed. Keep
POST /api/acp/agentsandrequireLogin=falsehunts. Oct 4 brief.