Atlassian races to patch critical unauthenticated file-read flaw Atlassian disclosed a critical arbitrary file access vulnerability on October 5, 2026, and by October 6 confirmed it affects eight self-managed data-center product lines: Bamboo, Bitbucket, Confluence, Crowd, Crucible, Fisheye, Jira Service Management, and Jira Software. Tracked as CVE-2026-21589 with a CVSS v3 severity score of