Atlassian Patches Critical Vulnerability Affecting 8 Products
Teaser from the source
Unauthenticated attackers could exploit the flaw to access specific files in the web application root directory. The post Atlassian Patches Critical Vulnerability Affecting 8 Products appeared first on SecurityWeek .
This is the RSS-feed teaser. Read the full article at the original source.
Read at SecurityWeek →More on Atlassian
Other advisories
- CVE-2026-56819highAtlassian Bamboo, Bitbucket, Confluence, Fisheye/Crucible, Jira Software und Jira Service Management: Mehrere Schwachstellen
- CVE-2026-21589highAtlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye und Jira): Schwachstelle ermöglicht Offenlegung von Informationen
- CVE-2026-21589noneSecurity Advisory 2026-015 — Critical Vulnerability in Multiple Atlassian Products
- CVE-2026-47838highAtlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, und Jira): Mehrere Schwachstellen
- CVE-2026-47838highAtlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere Schwachstellen
- CVE-2026-77258noneMCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path()
- CVE-2026-77250noneMCP Atlassian: OAuth fallback token storage writes plaintext access and refresh tokens with group-readable permissions
- CVE-2026-77249noneMCP Atlassian: Incomplete fix for GHSA-7r34-79r5-rcc9: redirect-based SSRF via unhooked requests session in Jira user-permission lookup
Other news entries
- Newssecurityweek2026-10-08Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication
- Newssans-isc-diary2026-10-07Scans for Atlassian vulnerablity (CVE-2026-21589), (Wed, Oct 7th)
- Newsbleepingcomputer2026-10-07Hackers exploit critical Atlassian flaw after public PoC release
- Newsthehackernews2026-10-07Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details
- Vulnerabilitybsi-cert-bund-wid2026-10-07Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye und Jira): Schwachstelle ermöglicht Offenlegung von Informationen
- Newscsoonline2026-10-07Atlassian’s critical flaw turns eight enterprise products into one big security problem
- Newsbleepingcomputer2026-10-06Atlassian warns of critical file-access flaw in Jira, Confluence
- Newsncsc-nl2026-10-06NCSC-2026-0402 [1.00] [M/H] Kwetsbaarheid verholpen in Atlassian Data Center producten
Source: https://www.securityweek.com/atlassian-patches-critical-vulnerability-affecting-8-products/
ID