24h | 7d | 30d

Overview

  • Atlassian
  • Bamboo Data Center

05 Oct 2026
Published
07 Oct 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
1.77%

KEV

Description

This is a vulnerability in Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center. Crowd Data Center, Crucible and Fisheye. This Arbitrary File Access vulnerability allows an unauthenticated attacker to access specific files within the web application root directory in affected versions. Exploitation requires prior knowledge of the target file's exact name and path; this vulnerability does not allow attackers to enumerate or list directory contents. In some configurations, there may be some sensitive files that make this highly severe. This vulnerability allows an unauthenticated remote attacker to access specific files within the web application root directory in affected versions. The vulnerability must be addressed for affected versions of: -- Bitbucket Data Center, introduced in version >= 4.6.0, fix versions: 9.4.26, 10.2.8, 10.5.1 -- Confluence Data Center, introduced in version >= 5.10.0, fix versions 9.2.26, 10.2.19 -- Crowd Data Center, introduced in version >= 2.11.0, fix versions 6.3.7, 7.0.3, 7.1.7, 7.2.4 -- Jira Software Data Center, introduced in version >= 7.1.0, fix versions 9.12.40, 10.3.26, 11.3.12 -- Jira Service Management Data Center, introduced in version >= 3.1.0, fix versions 5.12.40, 10.3.26, 11.3.12 -- Bamboo Data Center >= 7.0.1, fix versions 10.2.24, 12.1.12 -- Crucible, fix versions 4.9.15 -- Fisheye, fix version 4.9.15 -- Exploitation requires prior knowledge of the target file's exact name and path. The vulnerability does not include the capability to enumerate or list directory contents.

Statistics

  • 16 Posts
  • 24 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

Oh, Atlassian, never change! 😭

"CVE-2026-21589 - Arbitrary File Access Vulnerability impacts Multiple Products"

CVSS Score 9.3, so, you know, you better "Test that your rule blocks .. immediately adjacent to /".

APT /../../../../../../etc/passwd strikes again.

confluence.atlassian.com/secur

  • 8
  • 13
  • 0
  • 4h ago
Profile picture fallback

Critical Atlassian File Access Flaw Draws Attacks Across Eight Products esecurityplanet.com/news/news-

  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback

Critical Atlassian Data Center vulnerability CVE-2026-21589

Atlassian has disclosed CVE-2026-21589, a critical unauthenticated arbitrary file access vulnerability affecting Bitbucket Data Center, Confluence Data Center, Jira Software and Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible and Fisheye.

SecPoint Penetrator Partner Sign Up
secpoint.com/partner-signup.ht

#Atlassian #CyberSecurity #VulnerabilityManagement #SecPoint #Penetrator

  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback

⚠️ CRITICAL: Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details

A critical arbitrary file access vulnerability (CVE-2026-21589) in Atlassian Data Center products is under active exploitation as of public disclosure. Threat actors attempted exploitation within two hours of details going public, with potential access to credentials and sensitive files. All Atlass…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback
Threat actors are exploiting CVE-2026-21589, a critical Atlassian flaw that can expose sensitive files across multiple Data Center products. Threat actors have started exploiting CVE-2026-21589 (CVSS score of 9.3), a critical arbitrary file access flaw in Atlassian Data Center products. The vulnerability could allow attackers to access sensitive files under certain conditions. Affected products include […]
Atlassian Vulnerability Comes Under Attack Hours After Details Go Public
  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback

Atlassian Data Center CVE-2026-21589 (CVSS 9.3): arbitrary file read non autenticato via path traversal, sfruttamento osservato circa 2 ore dopo il write-up e la PoC di watchTowr (honeypot Previdian). Colpiti Jira Software/JSM, Confluence, Bitbucket, Bamboo, Crowd, Crucible, Fisheye (Cloud già patchato). La web-resource library converte '::' in '/', da cui il traversal sugli endpoint dei plugin.

  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback

Atlassian : une faille critique permet de lire des fichiers sur Jira, Confluence et Bitbucket it-connect.fr/atlassian-cve-20 #ActuCybersécurité #Cybersécurité #Vulnérabilité

  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback

Atlassian says CVE-2026-21589 affects all versions of eight self-hosted products. An unauthenticated attacker can read specific files when the exact path is known. Atlassian found no exploitation. Self-hosted customers should upgrade or restrict external access until patched.

confluence.atlassian.com/secur

#Cybersecurity #Atlassian #VulnMgmt

  • 0
  • 0
  • 0
  • 3h ago

Bluesky

Profile picture fallback
Irre IT-Welt: Atlassian Schwachstelle CVE-2026-21589 bereits nach 2 Stunden angegriffen, Nius zum 4. Mal seit Sommer 2025 gehackt, jetzt liegen die Daten von Abonnenten etc. offen. Es gab einen ccTLD-Registry-Hack von drei Ländern, und mehr. borncity.com/blog/2026/10...
  • 2
  • 1
  • 1
  • 4h ago
Profile picture fallback
📢 CVE-2026-21589 : Lecture de fichiers arbitraire pré-auth sur Atlassian Jira, Confluence et plus Cet article présente une analyse technique approfondie de CVE-2026-21589, une vulnérabilité critique divulguée par Atlassian dans… 🟢 vérification factuelle haute #Atlassian #Confluence #Cyberveille
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
Atlassian、JiraやConfluenceなどにCVSS 9.3の脆弱性「CVE-2026-21589」―認証なしで特定ファイルへアクセス可能 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #セキュリティニュース
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
📢 [VULN] Atlassian : une faille critique permet de lire des fichiers sur Jira, Confluence et Bitbucket - CVE-2026-21589 Vous administrez une instance Jira, Confluence ou Bitbucket hébergée sur vos propres serveurs ? #Vulnérabilité #CVE #Cyberveille
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
Atlassian Data Centerの脆弱性、詳細公開から2時間以内に悪用の試みを確認(CVE-2026-21589) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/48034/
  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback
Threat actors exploit CVE-2026-21589 in Atlassian Data Center products to read specific root files, with heightened impact when Jira integrates with Crowd credentials.
  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback
The latest update for #CyCognito includes "Emerging Threat: (CVE-2026-21589) Atlassian Data Center Arbitrary File Access via Path Traversal" and "Emerging Threat: (CVE-2026-94483) Next.js Server-Side Request Forgery via Image Optimization". #cybersecurity #EASM https://opsmtrs.com/44Srq0X
  • 0
  • 0
  • 0
  • 17h ago

Overview

  • Citrix NetScaler
  • ADC

27 Sep 2026
Published
29 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.5)
EPSS
1.08%

Description

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

Statistics

  • 3 Posts
  • 18 Interactions

Last activity: 4 hours ago

Fediverse

Profile picture fallback

Watchtowr have a good look at pray and spray #PitScaler exploitation. This isn’t the initial exploitation - their timeline should expand back to September 4th for that.

Also they make a good point re the latest SAML bug - by using it to DoS, it causes attacker commands in the logs to process immediately post reboot with PitScaler vuln. Not covered in blog: Attackers are actually doing this, they’re preloading the logs using the username field for failed logins.

watchtowr.com/intelligence/pos

  • 7
  • 11
  • 0
  • 4h ago
Profile picture fallback

Citrix NetScaler security alert: two actively exploited vulnerabilities

Citrix has confirmed exploitation of CVE-2026-88771 and CVE-2026-88772 in unmitigated NetScaler deployments.

The first can allow unauthenticated command execution. The second can lead to remote code execution or denial of service when DTLS is enabled.

linkedin.com/products/secpoint

#NetScaler #CyberSecurity #VulnerabilityManagement #SecPoint #Penetrator

  • 0
  • 0
  • 0
  • 15h ago

Bluesky

Profile picture fallback
Our @SOCRadar Threat Research Unit identified NetScaler C2, a toolkit built to automate CVE-2026-88771 exploitation, from target discovery to command execution. Injected commands may execute up to 24 hours later. Analysis & IOCs: socradar.io/blog/netscal...
  • 0
  • 0
  • 0
  • 9h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 2 Posts
  • 4 Interactions

Last activity: Last hour

Overview

  • VMware
  • VMware Workstation

07 Oct 2026
Published
07 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.3)
EPSS
0.26%

KEV

Description

VMware Workstation and Fusion contain an integer-overflow vulnerability. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Affected versions: - VMware Workstation: 25H2, 26H1 (fixed in 26H1u1) - VMware Fusion: 25H2, 26H1 (fixed in 26H1u1)

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 3 hours ago

Fediverse

Profile picture fallback

A VMware VMXNET3 vulnerability, CVE-2026-59346 (CVSS 9.3), allows VM escape. Full details and PoC exploit code are now public. Patch to 26H1u1.

securityonline.info/vmware-vmx

  • 1
  • 0
  • 0
  • 19h ago
Profile picture fallback

PoC Released for Critical VMware VMXNET3 Integer Overflow Flaw Enabling Guest-to-Host Code Execution (CVE-2026-59346)

CVE-2026-59346 affects VMware VMXNET3 and enables guest-to-host memory corruption. A public PoC crashes vmware-vmx. Patch Workstation and Fusion now

thecybersecguru.com/exploits/c

  • 0
  • 0
  • 0
  • 3h ago

Overview

  • kstover
  • Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder

22 Sep 2026
Published
22 Sep 2026
Updated

CVSS v3.1
HIGH (7.2)
EPSS
0.41%

KEV

Description

Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct submission URL, the script runs in the WordPress admin origin.

Statistics

  • 2 Posts

Last activity: 20 hours ago

Fediverse

Profile picture fallback

An active WordPress XSS campaign exploits Ninja Forms flaw CVE-2026-94504 and CVE-2026-93836 to plant hidden admin accounts. Patch now.

securityonline.info/wordpress-

  • 0
  • 0
  • 0
  • 20h ago

Bluesky

Profile picture fallback
WordPress「Ninja Forms」の脆弱性 CVE-2026-94504がサイバー攻撃に悪用 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #セキュリティ #セキュリティニュース
  • 0
  • 0
  • 0
  • 22h ago

Overview

  • IBM
  • DataPower Gateway 10.6.0

08 Oct 2026
Published
08 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.3)
EPSS
Pending

KEV

Description

IBM DataPower Gateway 10.6.0.0 through 10.6.0.10 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Statistics

  • 2 Posts

Last activity: 1 hour ago

Fediverse

Profile picture fallback

IBM fixes 23 IBM DataPower Gateway vulnerabilities, including critical RCE flaws CVE-2026-15762 and CVE-2026-16340. Upgrade to 11.0.0.3 now.

securityonline.info/ibm-datapo

  • 0
  • 0
  • 0
  • 6h ago

Bluesky

Profile picture fallback
~Cybergcca~ Splunk, HashiCorp Vault, Cisco, Elastic and IBM products require security updates. - IOCs: CVE-2026-14990 - #CVE202614990 #ThreatIntel #Vulnerabilities
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • IBM
  • DataPower Gateway 10.6CD

08 Oct 2026
Published
08 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
Pending

KEV

Description

IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write in the RFC2047 encoded-word parser.

Statistics

  • 2 Posts

Last activity: 6 hours ago

Fediverse

Profile picture fallback

CVE-2026-16340 (CRITICAL, CVSS 9.8): IBM DataPower Gateway 10.5.0.0 – 10.5.0.22, 10.6.0.0 – 10.6.0.10, 10.6.1 – 10.6.6, 11.0.0.0 – 11.0.0.2 vulnerable to remote code execution via out-of-bounds write. Patch priority high. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback

IBM fixes 23 IBM DataPower Gateway vulnerabilities, including critical RCE flaws CVE-2026-15762 and CVE-2026-16340. Upgrade to 11.0.0.3 now.

securityonline.info/ibm-datapo

  • 0
  • 0
  • 0
  • 6h ago

Overview

  • Sungrow
  • iSolarCloud

07 Oct 2026
Published
07 Oct 2026
Updated

CVSS v4.0
CRITICAL (9.2)
EPSS
0.34%

KEV

Description

Sungrow iSolarCloud before 2026 allows authentication bypass and account takeover via "login_type":"5" in a login request, potentially leading to "local blackouts on the whole continent" in Europe. An email address for the user_account property is required; however, a user can view the email address associated with their parent organization.

Statistics

  • 1 Post
  • 11 Interactions

Last activity: 22 hours ago

Bluesky

Profile picture fallback
Whoever wrote the advisory for CVE-2026-107194 deserves to be flogged
  • 0
  • 11
  • 0
  • 22h ago

Overview

  • Splunk
  • Splunk Enterprise

07 Oct 2026
Published
08 Oct 2026
Updated

CVSS
Pending
EPSS
0.15%

KEV

Description

Improper Access Control. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Common Vulnerabilities and Exposures (CVE) identifier assigned to each group. See Details for more information.

Statistics

  • 2 Posts
  • 3 Interactions

Last activity: 14 hours ago

Fediverse

Profile picture fallback

advisory.splunk.com

5 new Security Advisories for Cisco Splunk

Some of these are quite critical, e.g. CVE-2026-76281 & CVE-2026-76268 with each CVSS 9.8

#infosec #splunk

  • 1
  • 1
  • 0
  • 14h ago
Profile picture fallback

Splunk fixes 22 Splunk Enterprise vulnerabilities, including critical Patroni API flaw CVE-2026-76268 and CVE-2026-76281. Upgrade to 10.4.3 now.

securityonline.info/splunk-ent

  • 1
  • 0
  • 0
  • 19h ago

Overview

  • Splunk
  • Splunk Enterprise

07 Oct 2026
Published
08 Oct 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.40%

KEV

Description

In Splunk Enterprise versions below 10.4.3 and 10.2.7, an unauthenticated user with network access to the Patroni Representational State Transfer (REST) Application Programming Interface (API) on a search head cluster member could execute attacker-controlled operating-system commands. The vulnerability is possible because this interface does not require authentication for critical configuration operations. For more information see Sidecar configuration settings (https://help.splunk.com/en/data-management/splunk-enterprise-admin-manual/10.2/splunk-sidecars/sidecar-configuration-settings) in the Splunk documentation. Splunk Enterprise versions 10.0.x and 9.4.x are not affected.

Statistics

  • 2 Posts
  • 3 Interactions

Last activity: 14 hours ago

Fediverse

Profile picture fallback

advisory.splunk.com

5 new Security Advisories for Cisco Splunk

Some of these are quite critical, e.g. CVE-2026-76281 & CVE-2026-76268 with each CVSS 9.8

#infosec #splunk

  • 1
  • 1
  • 0
  • 14h ago
Profile picture fallback

Splunk fixes 22 Splunk Enterprise vulnerabilities, including critical Patroni API flaw CVE-2026-76268 and CVE-2026-76281. Upgrade to 10.4.3 now.

securityonline.info/splunk-ent

  • 1
  • 0
  • 0
  • 19h ago
Showing 1 to 10 of 118 CVEs