Two separate, serious security flaws have just been confirmed in Atlassian’s self-hosted Data Center products — the versions of Confluence, Jira, Bitbucket and related tools that businesses run on their own servers rather than through Atlassian Cloud. If that’s you, both are worth checking this week.
The short version
CVE-2026-21579 is an information-disclosure bug affecting self-hosted Confluence only (versions 7.17.0 through 10.2.0). A day later, CVE-2026-21589 turned out to be broader and more serious — rated 9.3 out of 10 on the severity scale — and hits every Data Center edition across the board: Confluence, Jira Software, Jira Service Management, Bitbucket, Bamboo, Crowd, Crucible and Fisheye. It allows an unauthenticated attacker to read specific files on the server if they already know the exact file path. Atlassian has released fixed versions for all affected products, and there’s no workaround other than patching.
If your business uses Atlassian Cloud rather than self-hosting, this doesn’t apply to you — Atlassian has already patched the cloud side, and no action is needed there.
Why self-hosted tools carry this kind of risk
Running your own server gives you control, but it also means your business — not a vendor — is responsible for noticing when a patch lands and applying it. Cloud software gets patched centrally and automatically; self-hosted software only gets patched when someone actually does it. Vulnerabilities like this one tend to surface in vendor security advisories first, then get picked up by attackers scanning the internet for unpatched servers soon after. The window between “patch available” and “patch applied” is where the actual risk sits.
As of the most recent check, there’s no confirmed active exploitation of either flaw yet — but that’s exactly the point at which patching matters most, before it becomes urgent.
What to check this week
1. Confirm whether your business runs any Atlassian Data Center product (Confluence, Jira, Bitbucket, Bamboo, Crowd, Crucible or Fisheye) on its own infrastructure, rather than through Atlassian Cloud. 2. If so, check the version against Atlassian’s published fixed versions for CVE-2026-21589 and CVE-2026-21579 (for example, Confluence Data Center 9.2.26 or 10.2.19 and later). 3. Patch promptly rather than scheduling it for “whenever” — this is exactly the kind of gap that gets found by automated scanning, not by someone targeting your business specifically.
If you’re not sure which Atlassian setup your business is actually running, or want someone to confirm the patch has genuinely gone through, our cybersecurity team can take a look rather than you having to dig through server configs yourself.
Self-hosted software gives you more control — it also means nobody else is going to patch it for you.