Skip to content
Attacks on Atlassian Data Center vulnerability have begun

Attacks on Atlassian Data Center vulnerability have begun

Heise.De • October 8, 2026

On Monday, a critical security vulnerability in several Atlassian Data Center products became known. Malicious actors from the internet can exploit it to bypass authentication and read certain files, which can, for example, provide access to systems and thus compromise them. And that is precisely what is already happening. IT managers should act quickly and check whether they have installed the available updates or at least implemented the countermeasures specified by Atlassian. They should also examine access logs for traces of attacks, as Atlassian advises.

On X, the IT security company Previdian warned that it had discovered the first attacks on its honeypot systems. The company names three IP addresses as indicators of compromise (IOC): 38.60.157[.]86, 146.70.187[.]234, and 159.26.119[.]225. According to them, exploit attempts on the vulnerability CVE-2026-21589 (CVSS4 9.3 , risk “ critical ”) originated from there. A vulnerability entry at the company provides further information the gap. According to Previdian, exploit attempts were initially detected on the honeypot systems, and the vulnerability was subsequently classified as exploited, which, according to the company, is also confirmed by third-party sources. Furthermore, a proof-of-concept exploit is available, which simplifies and accelerates practical exploitation. On X, the IT security researchers also state that a Nuclei template has been published and therefore increased attack attempts are to be expected. At the time of reporting, Previdian counted 156 attack attempts from 25 IP addresses in eight countries.

The Atlassian vulnerability has been making waves since Wednesday . The IT security researchers at watchTowr finally untangled the convoluted wording in Atlassian’s security notice and explained its actual scope. In environments with multiple Atlassian applications running in parallel on-premises, such as Jira, Confluence, and Bitbucket, “Crowd” is used. This is Atlassian’s own single sign-on software. Each app requires access credentials to Crowd, which are stored in a configuration file. The watchTowr experts demonstrated that they could use the critical security vulnerability to access this file, read the password, and thus create an admin access to the attacked Jira ticketing system. The security flaw therefore enables unauthorized admin access from the network without prior login.

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.

Extracted Entities

Domains (1)

Tools (1)