Cyber Threat Brief — October 6 2026

⚠️ This report is AI-generated. Always validate findings.

1. Atlassian Data Center unauth web-root file read — CVE-2026-21589

TL;DR: Atlassian disclosed CVE-2026-21589 on 2026-10-05 (CVSS 9.3): an unauthenticated attacker who already knows an exact file path can read that file from the web application root on eight self-hosted Data Center products. Cloud is patched with no exploitation found. Inventory every internet-facing Jira, Confluence, Bitbucket, Bamboo, Crowd, Crucible, and Fisheye node and move it to a fixed build before you lean on the WAF regex.

What’s New:

  • One CVE covers Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye Data Center. Exploitation needs the exact name and path; directory listing is not part of the bug. Atlassian still rates impact High on confidentiality (and on other systems in the CVSS 4.0 vector).
  • Fixed builds as of 2026-10-06 media and product tickets: Bitbucket 9.4.26 / 10.2.8 / 10.5.1; Confluence 9.2.26 / 10.2.19; Jira Software 9.12.40 / 10.3.26 / 11.3.12; JSM 5.12.40 / 10.3.26 / 11.3.12; Bamboo 10.2.24 / 12.1.12; Crowd 6.3.7 / 7.0.3 / 7.1.7 / 7.2.4; Crucible and Fisheye 4.9.15. Crowd’s 7.1 line is messy in the CVE record (7.1.1) versus the product ticket (7.1.7); take the ticket’s fixed list and confirm against your branch release notes before you close the change.
  • Temporary bridge (not a patch): WAF/reverse-proxy regex that blocks .. immediately next to /, \, or :: (including nested URL encoding). Confluence/Jira/JSM/Bamboo/Crowd can also use Tomcat RewriteValve + rewrite.config; Bitbucket uses a matching rule at the top of app/WEB-INF/urlrewrite.xml on every node and mirror. Crucible/Fisheye get the WAF option only.
  • Atlassian says Cloud is already patched and its investigation found no evidence of exploitation. Self-hosted exposure is on you: URL-decode access logs up to twice and hunt for .. beside /, \, or ::, or replay the vendor block pattern over raw lines. PoC-in-GitHub and nuclei-templates had no CVE-2026-21589 entry at draft time.

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
Self-hosted Atlassian Data Center builds below Bitbucket 9.4.26/10.2.8/10.5.1, Confluence 9.2.26/10.2.19, Jira Software 9.12.40/10.3.26/11.3.12, JSM 5.12.40/10.3.26/11.3.12, Bamboo 10.2.24/12.1.12, Crowd 6.3.7/7.0.3/7.1.7/7.2.4, Crucible/Fisheye 4.9.15Vulnerable appT1190App admin → System info / CATALINA_HOME install inventory / CMDBList every self-hosted node (including Bitbucket mirrors). If the running build is below the fixed line for that product branch, upgrade to the matching fixed build. Prefer a fixed LTS when you cannot jump to the newest train.
Atlassian WAF/proxy regex blocking .. adjacent to /, \, or :: (nested %25 / %2e / %2f / %5c / %3a forms included)Interim mitigationT1190WAF / reverse proxy / load balancer policyIf you cannot upgrade today, deploy the vendor regex on the edge in front of every public Atlassian DC VIP. Test with encoded .. probes. Treat this as a bridge only.
Tomcat RewriteValve + WEB-INF/rewrite.config (Confluence, Jira Software, JSM, Bamboo, Crowd) or Bitbucket app/WEB-INF/urlrewrite.xml rule returning 404Host mitigationT1190conf/server.xml, product WEB-INF, Bitbucket urlrewrite.xmlOn each cluster/mirror node, install the vendor rewrite rule, restart, and confirm a crafted ../ URL returns 404 before the app handles it. Do not skip mirrors.
Access-log lines where URL-decoded path (up to two decode passes) shows .. next to /, \, or ::Hunt / IR pivotT1190Access logs / reverse proxy / WAFDecode each request line up to twice and flag .. adjacent to /, \, or ::, or run Atlassian’s block pattern over raw lines. Preserve matching windows; upgrade first, then decide whether the hit returned a file.

Detection

SourceRuleGap
Splunk ESCUNone — verifiedConfluence ESCU stories (CVE-2022-26134, CVE-2023-22515, CVE-2023-22527) match OGNL ${ / privilege-escalation paths, not .. web-root reads for CVE-2026-21589.
ElasticNone — verifiedLocal elastic_dr tree has no rule whose logic targets Atlassian web-root ../ reads for this CVE.
SigmaNone — verifiedPath Traversal Exploitation Attempts only matches hard-coded ../../../etc/ / Windows / double-encoded etc strings. Emerging-threat Confluence/Bitbucket rules cover older CVEs (2019–2023). None name CVE-2026-21589.

Hunt hint: Pull version from every internet-reachable Atlassian DC VIP today. If any node sits below the fixed line for its branch, either upgrade or take it off the public internet and apply the WAF/rewrite bridge. Then sweep seven days of access logs with Atlassian’s double-decode .. hunt. A hit is a lead for IR, not automatic proof a sensitive file left the box — Atlassian does not publish which filenames matter in which configs.

Sources: The Hacker News · CONFSERVER-104488 · JSDSERVER-16809 · BSERV-20604 · JRASERVER-79546 · OpenCVE CVE-2026-21589


Status Updates

  • CVE-2026-88779 (NetScaler): CISA KEV due TOMORROW 2026-10-07; forensic triage Yes. Still vendor/KEV DoS on SAML SP/IdP. Fixed builds 14.1-73.41 / 13.1-64.28 / FIPS 14.1-73.41 / NDcPP 13.1-37.282. No new KEV add overnight (catalog still 2026.10.04, count 1734). Oct 5 brief.
  • CVE-2026-104286 (FortiMail): KEV due was 2026-10-04; forensic triage Yes. Singapore CSA restated active exploitation on 2026-10-06. Previdian sensors reported probe volume into 2026-10-06 (X post cites POST /api/v1/ibe/import with multipart ../ fields — treat as sensor-attributed, not a Fortinet FG-IR path). Keep IBE disable / management ACL, /data/etc/ld.so.preload, and liblog.so hunts; SecPod still framed fixed builds as upcoming (8.0.2, 7.6.7, 7.4.9). Oct 2 brief.
  • CVE-2026-102489 (Zammad): KEV due was 2026-10-05; forensic triage Yes. Confirm interim 7.2.0 and DIVD IOC script. Oct 3 brief.
  • CVE-2026-102490 (Zammad): KEV due was 2026-10-05; forensic triage Yes. Local zammad to root; no confirmed fixed build beyond leaving the affected line. Oct 3 brief.
  • CVE-2026-61500 (Rejetto HFS): Media wave (SecurityWeek / BleepingComputer 2026-10-05) restates VulnCheck canaries; still not CISA KEV. Keep 3.0.0–3.2.0 → ≥3.2.1, /~/api/loginSrp1, server_code, and 173.239.211.248/249. Oct 4 brief.
  • CVE-2026-88062 (OmniRoute): No material change. Version line still disputed. Keep POST /api/acp/agents and requireLogin=false hunts. Oct 4 brief.