Cyber Threat Brief — October 7 2026
1. Atlassian CVE-2026-21589 — PoC paths, Crowd chain, scanning
TL;DR: watchTowr published working pre-auth file-read paths for CVE-2026-21589 on 2026-10-06 (:: ↔ / in atlassian-plugins-webresource 6.0.7). A Nuclei template and DAG are public; SecurityOnline attributes Previdian honeypot hits as ITW. Patch internet-facing DC nodes today, then hunt the named ..:: resource paths and any Crowd REST abuse.
What’s New:
- Root cause is shared library
atlassian-plugins-webresource6.0.7 (patched 6.0.8):Router.unescapeSlashesmaps::to/, so..::bypasses slash-stripping and reads files inside the Tomcat webroot (not outside it). - Concrete unauth GETs: Jira
/download/resources/jira.webresources:color-picker-popup/images/..::..::..::..::..::WEB-INF::web.xml; Confluence/s/1/_/download/resources/com.atlassian.confluence.plugins.dashboard-actions/images/..::…::WEB-INF::web.xml; Bitbucket/s/1.0/_/download/resources/com.atlassian.bitbucket.server.bitbucket-webpack-INTERNAL:avatar/avatar/..::…::WEB-INF::urlrewrite.xml(Bitbucket blocksweb.xml). - Crowd-integrated Jira: read
WEB-INF/classes/crowd.propertiesfor plaintextapplication.password, then Crowd REST create-user / add tojira-administrators. Crowd IP allowlists blunt remote follow-on. - Public tooling: watchTowr DAG (
watchtowrlabs/watchTowr-vs-Atlassian-CVE-2026-21589); Nucleihttp/cves/2026/CVE-2026-21589.yaml(authors include DhiyaneshDk). SecurityOnline 2026-10-07 cites Previdian honeypot ITW — treat as sensor-attributed; exploitgrid on X still said “no exploitation observed” the evening of 2026-10-06.
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
| Self-hosted Atlassian DC builds below Bitbucket 9.4.26/10.2.8/10.5.1, Confluence 9.2.26/10.2.19, Jira Software 9.12.40/10.3.26/11.3.12, JSM 5.12.40/10.3.26/11.3.12, Bamboo 10.2.24/12.1.12, Crowd 6.3.7/7.0.3/7.1.7/7.2.4, Crucible/Fisheye 4.9.15 | Vulnerable app | T1190 | App admin → System info / install inventory / CMDB | Inventory every internet-facing node (incl. Bitbucket mirrors). If below the fixed line for that branch, upgrade to the matching fixed build before relying on WAF. |
atlassian-plugins-webresource-6.0.7.jar (patched 6.0.8) | Vulnerable library | T1190 | $CATALINA_HOME / product WEB-INF/lib inventory | On each node, confirm the webresource JAR is ≥6.0.8 after upgrade; if 6.0.7 remains, the host is still vulnerable even if the product UI version looks current. |
GET …/images/..::..::…::WEB-INF::web.xml (Jira/Confluence) or …/avatar/..::…::WEB-INF::urlrewrite.xml (Bitbucket) | Exploit path | T1190 | Access / reverse-proxy / WAF logs | Double-URL-decode request lines and alert on ..:: next to resource download paths above, or on decoded WEB-INF reads via /download/resources/ / /s/*/download/resources/. Preserve matching windows for IR. |
WEB-INF/classes/crowd.properties with plaintext application.password | Sensitive file / pivot | T1552.001 | Access logs + Crowd audit / REST logs | If Crowd is wired in, treat any successful read of crowd.properties as credential theft. Rotate the Crowd application password, then hunt Crowd REST user-create and jira-administrators group adds. |
watchTowr DAG + Nuclei template CVE-2026-21589.yaml | Scanner / PoC | T1190 | External scan telemetry / attack surface mgmt | Authorize DAG/Nuclei only against owned hosts to validate exposure. Expect noisy third-party scans now that both are public. |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | None — verified | Confluence ESCU stories still match OGNL ${ / older privilege-escalation URLs, not ..:: web-resource reads for CVE-2026-21589. |
| Elastic | None — verified | Local elastic_dr has no rule whose logic targets Atlassian :: webresource traversal. |
| Sigma | None — verified | Path Traversal Exploitation Attempts only matches hard-coded etc/windows/lib/password strings — would miss WEB-INF::web.xml via ::. Older Atlassian ET rules cover 2019–2023 CVEs. |
Hunt hint: Pull versions (and the webresource JAR) from every public Atlassian DC VIP. Upgrade or pull off-net first. Sweep seven days of access logs for decoded ..:: on the Jira/Confluence/Bitbucket resource paths above and for crowd.properties hits. On Crowd, review recent REST user creates and jira-administrators membership changes.
Sources: watchTowr Labs · SecurityOnline ITW/Nuclei · watchTowr DAG · Nuclei CVE-2026-21589.yaml · Oct 6 brief
2. ClickFix cache-smuggles VBScript via browser cache
TL;DR: Microsoft Threat Intelligence describes a ClickFix variant that pre-fetches a VBScript into the browser cache as a fake PNG, then uses a short Run-dialog command to find Firefox f_* cache files by size, copy to %LOCALAPPDATA%\Temp\t.vbs, and run wscript.exe — bypassing the ~260-character Run limit. Hunt RunMRU, t.vbs/wscript, and the named C2 hosts; do not rely on download events alone.
What’s New:
- Compromised sites stage the payload in cache before the paste step, so the Run command only has to locate and launch what is already local.
- Chain: cmd enumerates
f_*under%LOCALAPPDATA%\Mozilla\Firefox\Profiles, size-matches, copies to%LOCALAPPDATA%\Temp\t.vbs, executes withwscript.exe; WMI host harvest; fetchesv.ps1fromcocojambo[.]us[.]com/alfa; latercab.dat; injects intotimeout.exe; further stages fromcapsysnet[.]vg/ciliabula[.]cc. - MS guidance: cloud/web/network protection, app control, PowerShell script-block logging; hunt RunMRU, browser-cache activity, WScript/PowerShell children, scheduled tasks — beyond download events.
- Classic FakeCAPTCHA/ClickFix public rules still help on the paste/RunMRU stage, but they do not encode the
f_*size-match →t.vbscache-smuggle specifically.
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
%LOCALAPPDATA%\Temp\t.vbs created then executed by wscript.exe | Process / file IOC | T1059.005 | Sysmon 1/11, EDR process+file | Alert when wscript.exe runs %LOCALAPPDATA%\Temp\t.vbs (or a freshly copied .vbs under Temp) shortly after a Run-dialog / explorer parent. Quarantine the host and collect the script. |
cmd.exe enumerating f_* under %LOCALAPPDATA%\Mozilla\Firefox\Profiles then copying a size-matched file to Temp | Process behavior | T1036 / T1059.003 | Sysmon 1, EDR command line | Hunt cmd.exe command lines that recurse Firefox Profiles for f_* and copy to Temp; treat size-match-only (no content marker) as this campaign’s tell. |
Domains cocojambo[.]us[.]com (path /alfa → v.ps1), capsysnet[.]vg, ciliabula[.]cc | Network IOC | T1071.001 | Proxy / DNS / firewall | Block and retrospectively query DNS/proxy for these three hosts; prioritize endpoints that also show t.vbs/wscript or RunMRU activity. |
Process injection into newly launched timeout.exe followed by PowerShell outbound | Process behavior | T1055 | Sysmon 1/8/10, EDR | Hunt timeout.exe started then injected, especially when its child is PowerShell reaching the C2 domains above. |
| RunMRU registry values with short cmd/wscript lines after fake CAPTCHA lures | Hunt pivot | T1204.001 | Sysmon 13 / Registry, Splunk ESCU RunMRU | Query RunMRU for recent cmd/wscript/powershell pastes; correlate with browser parents and the Temp t.vbs artifact within minutes. |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | Partial — Windows PowerShell FakeCAPTCHA Clipboard Execution; Windows RunMRU Command Execution (Fake CAPTCHA story) | Catch classic CAPTCHA-string / RunMRU paste. Do not match f_* size-match → Temp\t.vbs cache smuggle. |
| Elastic | Partial — Potential Fake CAPTCHA Phishing Attack | Matches explorer→powershell/cmd/mshta with CAPTCHA/verification strings. Misses cache-file size enumeration and t.vbs unless those strings appear. |
| Sigma | Partial — Potential ClickFix Execution Pattern - Registry; Potentially Suspicious Command Executed Via Run Dialog Box - Registry | RunMRU http/captcha/LOLBin patterns. No f_* / t.vbs / Firefox-cache logic. |
Hunt hint: Pull 14 days of RunMRU and wscript.exe children. Stack any Temp\t.vbs create+execute with Firefox profile f_* file reads and DNS to the three C2 domains. Educate users that a CAPTCHA must never ask them to paste into Run.
Sources: The Hacker News · iTnews (MS TI summary)
Status Updates
- CVE-2026-88779 (NetScaler): CISA KEV due TODAY 2026-10-07; forensic triage Yes. Still vendor/KEV DoS on SAML SP/IdP. Fixed builds 14.1-73.41 / 13.1-64.28 / FIPS 14.1-73.41 / NDcPP 13.1-37.282. No new KEV add overnight (catalog still 2026.10.04, count 1734). Oct 5 brief.
- CVE-2026-104286 (FortiMail): KEV due was 2026-10-04; forensic triage Yes. FG-IR-26-175 solution update 2026-10-05 now names fixed builds 8.0.2, 7.6.7, 7.4.9; 7.2 → migrate to 7.4+. Keep IBE disable / management ACL and
/data/etc/ld.so.preload/liblog.sohunts until upgraded. Oct 2 brief. - CVE-2026-102489 (Zammad): KEV due was 2026-10-05; forensic triage Yes. Confirm interim 7.2.0 and DIVD IOC script. Oct 3 brief.
- CVE-2026-102490 (Zammad): KEV due was 2026-10-05; forensic triage Yes. Local
zammadto root; no confirmed fixed build beyond leaving the affected line. Oct 3 brief. - CVE-2026-61500 (Rejetto HFS): Still not CISA KEV. Keep 3.0.0–3.2.0 → ≥3.2.1,
/~/api/loginSrp1,server_code, and 173.239.211.248/249. Oct 4 brief. - CVE-2026-88062 (OmniRoute): No material change. Version line still disputed. Keep
POST /api/acp/agentsandrequireLogin=falsehunts. Oct 4 brief.