Critical RCE Vulnerability in Bamboo Data Center Exposed

Critical RCE Vulnerability in Bamboo Data Center Exposed

First seen 20 Mar 2026, 10:27 UTC TenableGbhackersCybersecuritynewsHeise.De 74.0

Article Content

Browse articles
ThreatCluster

A high-severity Remote Code Execution (RCE) vulnerability, tracked as CVE-2026-21570, has been identified in Bamboo Data Center versions 9.6.0 through 12.1.0. This vulnerability, with a CVSS score of 8.6, allows authenticated attackers to execute arbitrary malicious code on affected systems. Atlassian has advised users to upgrade to fixed versions: 9.6.24 or higher, 10.2.16 or higher, and 12.1.3 or higher. The vulnerability was reported via Atlassian's internal program and poses a significant risk to enterprises using this platform for software build and release management. Security teams are urged to apply the necessary updates immediately to mitigate potential exploitation. The vulnerability was published on 2026-03-17.

Key Points: • CVE-2026-21570 is a high-severity RCE vulnerability in Bamboo Data Center. • Affected versions include 9.6.0 to 12.1.0, with a CVSS score of 8.6. • Users are advised to upgrade to specified fixed versions to prevent exploitation.

Timeline

2026-03-17
CVE-2026-21570 published
2026-03-18
Tenable article published detailing the vulnerability
2026-03-20
Cybersecuritynews article published urging users to apply patches