Find notable cyber news and cases, enriched with sources, timelines, and signals.

Atlassian Data Center products path traversal (CVE-2026-21589)

Vulnerability
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

Atlassian disclosed CVE-2026-21589, a path traversal vulnerability in 8 self-hosted Data Center products that can let a no-login attacker read specific files in each product's web application root directory. Atlassian published fixed versions for the affected products and said cloud customers do not need to take action. The advisory also recommends temporary network-blocking mitigations until systems are upgraded.

Related Happenings

GitLab Self-Hosted AI Gateway immediate update advisory (CVE-2026-90970)

Advisory/Mitigation
H score41 First: 02.10.2026 19:20 Last: 02.10.2026 19:20 Sources 1

About this happening: GitLab issued immediate update guidance for GitLab Self-Managed customers running Self-Hosted AI Gateway after fixing CVE-2026-90970, a flaw that could allow arb...

Fortinet FortiMail mitigation guidance for CVE-2026-104286

Advisory/Mitigation
H score49 First: 02.10.2026 01:42 Last: 02.10.2026 01:42 Sources 1

About this happening: Fortinet issued mitigation guidance for CVE-2026-104286 in FortiMail, warning administrators to use workarounds while the flaw is being actively exploited. The adv...

Linux kernel active exploitation wave (CVE-2025-39964, CVE-2026-53266, CVE-2025-39682)

Exploitation Wave
H score35 First: 21.09.2026 23:12 Last: 21.09.2026 23:12 Sources 1

About this happening: CISA has warned that three Linux kernel vulnerabilities are being exploited in attacks, including one critical flaw, creating immediate risk for exposed systems. The w...

Red Hat Linux kernel advisory update for active exploitation

Advisory/Mitigation
H score53 First: 19.09.2026 09:24 Last: 19.09.2026 09:24 Sources 1

About this happening: Red Hat updated its Linux kernel advisories on September 19, 2026 to flag active exploitation of CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964, pu...

CISA adds Linux kernel flaws to KEV catalog under BOD 26-04

Public Sector Action
H score36 First: 19.09.2026 09:24 Last: 19.09.2026 09:24 Sources 1

About this happening: CISA added three Linux kernel flaws to its KEV catalog after evidence of active exploitation, forcing federal remediation prioritization. Under BOD 26-04, FC...

Timeline

  1. 06.10.2026 09:58 1 articles · 3h ago

    Atlassian discloses CVE-2026-21589 in eight self-hosted Data Center products

    Initial Disclosure

    Atlassian disclosed CVE-2026-21589, a path traversal flaw affecting 8 self-hosted Data Center products, and said an attacker with no login access could read specific files in each product's web application root directory.

    Show sources
  2. 06.10.2026 09:58 2 articles · 3h ago

    Atlassian publishes fixed versions and temporary blocking guidance for CVE-2026-21589

    Mitigation Patch Update

    Atlassian published fixed versions for the affected products, said its affected cloud products had already been patched and its investigation found no evidence of exploitation, and advised customers who cannot upgrade immediately to restrict outside access or apply temporary blocking rules on a WAF or reverse proxy, Tomcat RewriteValve, or Bitbucket's urlrewrite.xml.

    Show sources