Atlassian patches critical file access flaw hitting every Data Center version of eight products
Atlassian says CVE-2026-21589 lets unauthenticated attackers read files from the web application root of Jira, Confluence, Bitbucket and five other self-hosted products. All versions are affected.
