NewsThe Hacker News2026-10-06 06:58 UTC
Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
Linked advisories
- CVE-2026-21589h3.
- CVE-2026-21589Sicherheitsluecke -- CVE-2026-21589
- CVE-2026-21589Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye und Jira): Schwachstelle ermöglicht Offenlegung von Informationen
- CVE-2026-21589Security Advisory 2026-015 — Critical Vulnerability in Multiple Atlassian Products
More on Unauthenticated
Other advisories
- CVE-2026-107805highNginx UI: Unauthenticated signed-request body staging can exhaust temporary storage
- CVE-2026-107805noneNginx UI: Unauthenticated signed-request body staging can exhaust temporary storage
- CVE-2026-75597mediumpyLoad: Unauthenticated access to /web/<path:filename> bypasses authentication on sensitive templates and leaks internal error details via exception attribute typo
- CVE-2026-75597nonepyLoad: Unauthenticated access to /web/<path:filename> bypasses authentication on sensitive templates and leaks internal error details via exception attribute typo
- CVE-2026-90440noneApache Thrift: An exception escaping a libevent callback stops the D library's non-blocking server, allowing an unauthenticated remote attacker to deny service
- CVE-2026-86537noneApache Thrift: A truncated HTTP request stops the D library's server, allowing an unauthenticated remote attacker to deny service
- CVE-2026-82459noneApache Thrift: Integer underflow in C++ THeaderTransport allows an unauthenticated remote peer to terminate a 32-bit process
- CVE-2026-63772noneApache Thrift: Unauthenticated single-packet crash of Go Thrift servers via the THeader transform count
Other news entries
- Newscsoonline2026-10-09Exposed Nvidia GPU monitors can reveal AI infrastructure secrets
- Newsthehackernews2026-10-07Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
- Newssecurityweek2026-10-07Atlassian Patches Critical Vulnerability Affecting 8 Products
- Newsthehackernews2026-10-02Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
- Newsthehackernews2026-10-02Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
- Newssecurityweek2026-10-01Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability
- Newsfortinet-psirt2026-10-01Improper limitation of a pathname to a restricted directory
- Newsthehackernews2026-09-30Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
Source: https://thehackernews.com/2026/10/critical-atlassian-flaw-lets.html
ID