Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

The Hacker News - Oct 6, 2026

A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must already know a file's exact name and path and cannot list what the directory holds. Atlassian disclosed the flaw, CVE-2026-21589, on October 5, rated it 9.3 out of 10, and

Read full article

More News

24-7 Reporters

24-7 Reporters publishes up-to-the-minute news 24 hours a day, 7 days a week. Our certified reporters are among the most experienced, well-trained and talented across the globe, covering issues resonating progressives in every corner of the world.

Sign Up