P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Seven of Atlassian's 19 fixed builds for CVE-2026-21589 are on lines that leave support by 30 December

Atlassian's bulletin for CVE-2026-21589 lists 19 fixed builds across eight Data Center products; seven sit on release lines whose support ends between 3 and 30 December 2026. No exploitation is stated, and the CVE record's Crowd fix, 7.1.1, disagrees with the bulletin's 7.1.7.

By Parminder Kumar Sharma · · 17 min read

Editorial illustration for the briefing: Seven of Atlassian's 19 fixed builds for CVE-2026-21589 are on lines that leave support by 30 December

Nineteen fixed builds, and a short runway under seven of them

Atlassian's bulletin for CVE-2026-21589 names eight products and lists 19 fixed builds between them. Counted against Atlassian's own end-of-support policy page, seven of those 19 builds sit on release lines whose support ends between 3 and 30 December 2026, which is 58 to 85 days from Tuesday 6 October. Three more sit on lines that page does not list, and nine run into 2027 or 2028. These counts are derived by this site from the two Atlassian pages, and the map further down draws every one of them.

That is a fact about how long this week's patch will carry you. It does not establish that anyone is exploiting the flaw. Atlassian says its investigation found no evidence of exploitation in Cloud, says it cannot confirm whether any Data Center instance was affected, and the CISA catalogue of known exploited flaws did not list the CVE when read. Nor does the count say which files a stranger could read on your instance, how many instances are exposed to the internet, or whether the flaw has anything to do with earlier Atlassian bugs. The primaries are silent on all three, and so is this article.

State of each source when read on the morning of Tuesday 6 October 2026, UTC. Any of these can change; the times say when each was last read.

  1. Source
    Atlassian bulletin
    State when read
    Advisory release date 5 Oct 2026; page last modified 5 Oct 2026; no revision table on the page
    Read at (UTC)
    05:59, same as 05:36
  2. Source
    Atlassian public tickets (eight)
    State when read
    All eight Published and Fixed, resolved 5 Oct between 21:04 and 21:05 UTC
    Read at (UTC)
    05:59, same as 05:38
  3. Source
    CVE.org record
    State when read
    PUBLISHED 5 Oct 21:30 UTC; last updated the same minute
    Read at (UTC)
    05:59, same as 05:35
  4. Source
    NVD record
    State when read
    Received, 5 Oct 22:16 UTC; no NVD or CISA-ADP score, no CWE
    Read at (UTC)
    05:59, same as 05:35
  5. Source
    CISA KEV catalogue
    State when read
    Version 2026.10.04, released 4 Oct 18:52 UTC, 1,734 entries; CVE-2026-21589 not listed
    Read at (UTC)
    05:59, same as 05:37

What the primaries say, and what they leave out

Everything in the Stated column below is on Atlassian's bulletin, its eight public tickets, the CVE.org record or the NVD record. The Not stated column is what none of them states. Reading the second as if it were the first is how a short advisory turns into a long rumour.

Stated and not stated, from the bulletin, the eight Atlassian tickets, the CVE.org record, the NVD record and the CISA KEV catalogue, read 6 October 2026.

  1. Topic
    Reach
    Stated
    Unauthenticated, over the network, no user interaction. Atlassian says to restrict internet access even where instances use authentication
    Not stated
    How many instances are exposed. No scan figure is quoted here
  2. Topic
    What is read
    Stated
    Specific files in the web application root. The exact name and path must be known. No directory listing
    Not stated
    Which files, or which configurations put sensitive ones there
  3. Topic
    Exploitation
    Stated
    Cloud: patched, no evidence of exploitation found. Data Center: Atlassian cannot confirm whether instances were affected
    Not stated
    Any exploitation of Data Center, any public exploit, who found the flaw, or when
  4. Topic
    Scope
    Stated
    All versions of eight Data Center products
    Not stated
    Which shared component is at fault, or why eight products share it
  5. Topic
    Fix
    Stated
    19 builds; release notes date 16 of them 5 Oct 2026 and Bitbucket's three 6 Oct 2026
    Not stated
    A fixed build in every supported line: 34 supported lines have none listed
  6. Topic
    Score
    Stated
    9.3 Critical, CVSS 4.0, Atlassian's own assessment
    Not stated
    An NVD, CISA-ADP or CVSS 3 score, or a CWE identifier
  7. Topic
    Server editions
    Stated
    The CVE record lists eight Server products as affected
    Not stated
    Anything about Server in the bulletin; most have no fix listed

Two dates are worth separating from discovery. The earliest of the eight public tickets was created on Friday 2 October at 04:26 UTC, three days and 16 hours before Atlassian resolved it, which shows the ticket existed, not when the flaw was found. The CVE identifier was reserved on 1 January 2026, 277 days before publication, which shows Atlassian reserves identifiers in advance, not that it knew of the flaw in January. By the dates on the bulletin the gap between Atlassian's email on Monday 5 October, as The Register reports it, and the bulletin is zero days.

The fix map: which line, which build, until when

Atlassian's advice is blunt: it "recommends patching to the fixed LTS version or later". Most fixed builds are on long-term-support lines. The exceptions are Bitbucket 10.5, which the policy page does not list, and three Crowd lines not marked LTS. Atlassian's security bug fix policy says critical fixes go to the latest feature release and to supported LTS releases. Support for each line runs two years from its first release, according to the policy page, last modified 22 September 2026. Put the bulletin and the policy page side by side and the runway is uneven.

A single column listing the 19 fixed builds in Atlassian's bulletin of 5 October 2026 under eight products. Seven builds sit on release lines whose support ends between 3 and 30 December 2026, 58 to 85 days after 6 October. Nine sit on lines that end support in 2027 or 2028. Three, Jira Software 9.12.40, Jira Service Management 5.12.40 and Bitbucket 10.5.1, sit on lines the policy page does not list.
Fixed builds from Atlassian's bulletin of 5 October 2026; support-end dates from Atlassian's support policy page, last modified 22 September 2026; day counts and tallies derived by this site from 6 October.

Four points follow from the map, each checkable on the two Atlassian pages.

Most supported lines have no fixed build. The policy page lists 34 other release lines that are still in support after 6 October and have no fixed build in the bulletin (derived: Bamboo 3, Bitbucket 7, Confluence 5, Crowd 1, Jira Software 9, Jira Service Management 9). A Confluence 9.5 site, supported to 4 June 2027, has no fixed 9.5 build to install. It has to move to a listed build or later. Confluence 9.1 left support on 3 October, three days before this article, and is on no fix path at all.

The Jira 9.12 and Service Management 5.12 lines are an open question. The Jira Software 9.12 release notes give 29 November 2025 as that line's end-of-life date, the policy page does not list 9.12 or 5.12, and Atlassian released 9.12.40 on 5 October 2026, 310 days after the stated date. The sources do not say whether support was extended. Anyone on those lines should ask Atlassian rather than assume.

Older versions are not cleared. Each of the eight tickets says versions that have reached end of life "may also be affected". That is a statement of untested scope, not of safety.

Server editions sit outside the bulletin. The CVE record lists eight Server products as affected, and Atlassian's Server end-of-support notice put the end of support at 15 February 2024, 963 days before this bulletin. The bulletin itself covers Data Center only.

A 9.3 built on what lies downstream

Atlassian scores the flaw 9.3, Critical, with the vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H, "per our internal assessment". It adds: "This is our assessment, and you should evaluate its applicability to your own IT environment." The score is Atlassian's alone. NVD had assigned none when read, and CISA-ADP had added none.

The vector says two different things. For the vulnerable system, confidentiality impact is high and integrity and availability impacts are none, which is what a read-only flaw should score. For the subsequent systems, the three metrics SC, SI and SA are all high. This site recomputed the score from the vector with two independent open-source implementations of the CVSS 4.0 specification: both return 9.3. Setting only SC, SI and SA to none returns 8.7, High, in both. So the whole step from High to Critical rests on the assumption that a file read leads to harm elsewhere. Atlassian's own caveat points the same way: "In some configurations, there may be sensitive files present that increase your risk."

That is not a criticism. A vendor cannot see your web root, so it plausibly scores a worst reasonable case; the bulletin does not explain its choice of values. The point is what the number cannot do: it cannot tell you which case you are in. Both 9.3 and 8.7 are above the 7.0 line that Cyber Essentials applies to CVSS 3 scores, though the versions differ, so the arithmetic changes the label and not the clock. The site has looked before at how two scoring versions of one flaw land in different bands.

The friendly-name fallacy runs both ways. "File access" sounds milder than remote code execution, and The Register is right that, in Atlassian's words, exploitation "requires prior knowledge of the target file's exact name and path" and directories cannot be listed. Those are stated preconditions and are true to the primary. What the primaries do not say is how hard the name and path are to know. This is judgement, labelled as such: Atlassian publishes its software, so the layout of a default install can be learned by anyone, and the precondition raises the bar for files an administrator added, not for files every install has.

Two further cautions on labels. The CVE record's problem type is free text, "Path Traversal (Arbitrary Read/Write)", with no CWE identifier, while the vector scores no integrity impact on the vulnerable system. Treat the flaw as read until Atlassian says otherwise. And Atlassian's block rule and detection advice both concern two dots next to a path separator, which suggests, as inference only, that the fault is in how the request path is handled. The bulletin names no component.

For context, not as a link: CISA's catalogue holds 13 Atlassian entries, three of them described as path traversal or arbitrary file read (CVE-2019-3398, CVE-2021-26085 and CVE-2021-26086). The class has been exploited in Atlassian products before. Nothing in the primaries connects any of those flaws to this one.

Where Atlassian's own records disagree

The bulletin is Atlassian's page. The CVE record is Atlassian's submission to the CVE programme. Both appeared on 5 October, the tickets and the record about 25 minutes apart, and they do not agree. For anyone who patches from a vulnerability scanner, a ticketing feed or a CVE-record parser, the record is the version they will see.

Disagreements among Atlassian's bulletin, its public tickets, its release notes, its download feed and its CVE.org record, read 6 October 2026.

  1. Item
    Crowd 7.1 fixed build
    One Atlassian source says
    Bulletin and the ticket's fix-version field: 7.1.7
    Another says
    CVE record: 7.1.1, released 27 Nov 2025, 312 days before the bulletin. Ticket text: 7.1.6, which the same ticket lists as affected
  2. Item
    Bamboo 10.2 fixed build
    One Atlassian source says
    Bulletin and CVE description: 10.2.24
    Another says
    CVE affected-version data: 10.2.4 and later. One third-party tracker page repeats it
  3. Item
    Release dates of the fixed builds
    One Atlassian source says
    Release notes: 5 Oct 2026 for 16 builds, 6 Oct for Bitbucket's three
    Another says
    Download feed: 2 Oct for two Jira builds, 6 Oct for four Crowd builds. Ticket version data differs again
  4. Item
    How far back
    One Atlassian source says
    Bulletin: all versions
    Another says
    CVE record: introduced in builds from Jira Software 7.1.0 and Service Management 3.1.0 (10 Feb 2016) to Bamboo 7.0.1 (10 Mar 2020); nothing for Crucible or Fisheye
  5. Item
    Editions
    One Atlassian source says
    Bulletin: Data Center only
    Another says
    CVE record: eight Server products also affected
  6. Item
    What the flaw allows
    One Atlassian source says
    Bulletin and vector: file access; no integrity impact on the vulnerable system
    Another says
    CVE problem type: Read/Write

The practical rule is short. Use the bulletin's build numbers, confirm the build you install is at or above the number for your line, and check the release notes page for that line. Do not let a scanner mark Crowd 7.1.1 or Bamboo 10.2.4 as fixed. The oldest line the record names was released more than ten and a half years before disclosure (3,890 days from 10 February 2016 to 5 October 2026, derived), but the record's start versions are the CVE submission's claim, not the bulletin's.

What discontinuing Data Center does and does not cover

The Register says Atlassian "decided to discontinue its datacenter software", and a reader could take from that one end date for all eight affected products. Atlassian's own end-of-life page says something narrower, and this article follows the vendor page.

Data Center end-of-life dates for the eight affected products, from Atlassian's end-of-life page and support pages read 6 October 2026. Day counts derived from 6 October 2026.

  1. Product
    Jira Software, Jira Service Management, Confluence and Crowd Data Center
    Atlassian's stated date
    End of life 28 Mar 2029 at 23:59 PST, then read-only
    Days
    904
  2. Product
    Bitbucket Data Center and Bamboo Data Center
    Atlassian's stated date
    "Will not end of life", via a Bitbucket Hybrid License
    Days
    no date
  3. Product
    Crucible and Fisheye
    Atlassian's stated date
    Support ends 15 May 2028; no new sales since 13 May 2025
    Days
    587

Through 28 March 2029 Atlassian promises technical support and security fixes for critical vulnerabilities for the affected Data Center products, and new customers have been unable to buy Data Center since 30 March 2026, 190 days ago. Existing customers can expand until 30 March 2028. After the end date the instance is read-only, and Atlassian says: "We strongly advise against keeping your product running in a read-only mode while connected to the internet."

Two UK points. First, Cyber Essentials requires in-scope software to be licensed and supported, and defines support as a vendor commitment with a stated end date; Atlassian's dates are those dates. Second, for bodies on an April to March financial year, the end-of-life date, 28 March 2029, is three days before that year closes on 31 March 2029, and the last day to expand, 30 March 2028, is one day before the year closing on 31 March 2028. That is judgement, not a source claim: a migration first funded in the 2028 to 2029 year starts in the last year of support.

The UK clocks, and what the NCSC does and does not say

Two published clocks apply to a self-hosted instance, and both start at release. The bulletin is dated Monday 5 October, and the release notes date 16 of the 19 fixed builds to the same day; Bitbucket's three say 6 October, a day later, with no time zone given.

Patching clocks from a 5 October 2026 release. NCSC vulnerability management guidance (published 12 Feb 2024, reviewed 1 May 2026, version 2.1) and Cyber Essentials Requirements for IT Infrastructure v3.3 (April 2026), read 6 October 2026.

  1. Clock
    5 days, internet-facing services and software
    Source
    NCSC best practice
    Counted from 5 Oct
    Saturday 10 Oct 2026
  2. Clock
    14 days, vendor-rated critical or high, or CVSS 3 base 7 or above
    Source
    Cyber Essentials v3.3
    Counted from 5 Oct
    Monday 19 Oct 2026
  3. Clock
    14 days, internal and air-gapped services
    Source
    NCSC best practice
    Counted from 5 Oct
    Monday 19 Oct 2026

Cyber Essentials counts "critical or high risk" by a CVSS 3 base score of 7 or more, or by the vendor's own wording. Atlassian publishes only a CVSS 4.0 vector and calls the flaw Critical, so the vendor-wording route applies; that is this site's reading. If the 2 October date in Atlassian's download feed for two Jira builds is the one that counts, the 14 days end on 16 October. The NCSC guidance also says that for an actively exploited internet-facing flaw you should check for compromise before updating. Exploitation is not established here, so that rule is not triggered, but the logs should be copied before any node restarts.

What the NCSC has said about this flaw: nothing found. Keyword searches of ncsc.gov.uk at about 06:57 BST on 6 October returned six items for "Atlassian" and three for "Confluence", all general guidance or research, and nothing about this CVE. Nothing found is specific to collaboration or developer tooling either. The closest guidance is general. The NCSC's 27 August 2026 alert on internet-exposed systems is operational-technology focused, but tells other organisations to keep an accurate inventory of internet-facing systems, apply vendor updates promptly, retire end-of-life equipment and register for the free Early Warning service. Early Warning works from the IP addresses and domains you register; whether it will flag this flaw is not stated. The NCSC's January 2025 paper on 'unforgivable' vulnerabilities lists CWE-22 path traversal and scores input validation, one of its mitigations, as easy, but says the scoring assumes mitigations are built in from the start and not retrofitted. With no code-level cause published, this article makes no forgivable or unforgivable call.

Who is exposed in the UK is not in the sources. There is no UK install count. Atlassian's own end-of-life page says "source code and CI/CD pipelines are mission-critical" and some organisations "may need to keep them self-managed". Judgement: that profile fits public bodies, universities, NHS trusts and defence suppliers that keep source code or tickets in-house, but the sources name no sector. The first item in Atlassian's shared-responsibility list is "Operating Atlassian software on private networks".

What sits in a web root is the open question. The bulletin does not list files. Atlassian's Confluence documentation puts the start-up configuration file, which holds database connection settings, in the home directory and not the installation directory. In that layout those settings are not under the web application. "In some configurations" is then the risk: a layout where someone has put configuration, backups, exports or scripts under the application directory. Whether yours is one of them is a check, not a guess.

What to do, in the order worth doing it

Take this with you

Order of work

  • Find every Atlassian instance and version: Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye, including test, staging, inherited and old Server-era installs. Use licence records, DNS and reverse proxy configuration, and ask who runs Crucible or Fisheye, which are easy to forget.
  • Take each internet-facing instance off the internet, or put it behind a VPN or single sign-on at the proxy, until it is patched. Atlassian says this applies even where instances use authentication.
  • For anything you cannot patch today, apply the block rule in the bulletin for your product, at the proxy or firewall, in Tomcat or in Bitbucket's rewrite file. Back up first, test it, and keep the patch date.
  • Patch to a build at or above the bulletin's number for your line, or move to a newer listed line. If your line has no fixed build, plan the move now. Use the bulletin's numbers, not the CVE record's, for Crowd and Bamboo.
  • Before restarting any node, copy web server, proxy and application access logs off the host.
  • Search the logs for as far back as you keep them. Atlassian's own advice is to decode each request line, up to two passes, and look for two dots next to a path separator, or to search raw lines with the bulletin's pattern. Look for successful responses as well as attempts, and for one source sending many differently shaped requests. No start date for any exploitation is stated, so the window is every retained log.
  • Rotate any secret that sat in a file under a web application directory, or that you cannot show did not. This is judgement: Atlassian does not tell you to rotate anything, and rotating costs less than not knowing.
  • Put the next upgrade in the plan: any instance patched to a line that ends support in December 2026 already has a date. Cyber Essentials needs supported software.
  • Register the organisation for NCSC Early Warning, and subscribe a named person to Atlassian's advisory emails so the next notice has an owner.

A block rule is a stopgap, not a fix. The site's earlier briefing One letter past the WAF covers what happens when a rule matches one spelling of a path and the attacker uses another. Atlassian's pattern is written to cover encoded forms, but only a patched build removes the dependence on any rule.

The question the score cannot answer

Atlassian has done the part a vendor can do: it published fixed builds, a block rule, detection advice and a plain statement that it cannot confirm whether any instance was affected. The score, the clocks and the end-of-life dates all assume something the sources cannot see, which is what sits under your web root and who last checked.

So the question is not whether this flaw is a 9.3 or an 8.7. For each Atlassian instance you run, can you name the one file under its web application directory that you would least want a stranger to read, and show who checked that it is not there?

Key facts

Sources

  1. PrimarySecurity bulletin for CVE-2026-21589, advisory release date 5 Oct 2026: affected products, fixed versions, CVSS 4.0 vector, mitigations, detection advice, Cloud statementAtlassianaccessed 2026-10-06
  2. PrimaryCVE.org record: published 5 Oct 2026 21:30 UTC, affected and unaffected version data, introduced-in versions, problem type, 4.0 vectorCVE Program (CNA: Atlassian)accessed 2026-10-06
  3. PrimaryNVD record: status Received, published 5 Oct 2026 22:16 UTC, Atlassian's score only, no CWE, no CISA-ADP dataNIST National Vulnerability Databaseaccessed 2026-10-06
  4. PrimaryKnown Exploited Vulnerabilities catalogue, version 2026.10.04, 1,734 entries; CVE-2026-21589 absent; 13 Atlassian entriesCISAaccessed 2026-10-06
  5. PrimaryPublic ticket for Crowd: fix-version field 7.1.7, description table 7.1.6, creation and resolution times; the seven sibling tickets were read the same wayAtlassianaccessed 2026-10-06
  6. PrimaryPublic ticket for Confluence: earliest created of the eight, 2 Oct 2026 04:26 UTC; end-of-life versions may also be affectedAtlassianaccessed 2026-10-06
  7. PrimaryData Center end of life: 28 Mar 2029 for Jira Software, Jira Service Management, Confluence and Crowd; Bitbucket and Bamboo not ending; sales and support datesAtlassianaccessed 2026-10-06
  8. PrimaryAtlassian End of Support Policy, last modified 22 Sep 2026: end-of-support date of every release line; Fisheye and Crucible support to 15 May 2028Atlassianaccessed 2026-10-06
  9. PrimarySecurity Bug Fix Policy: critical fixes to the latest feature release and supported LTS releases; shared responsibility listAtlassianaccessed 2026-10-06
  10. PrimaryServer end of support: 15 Feb 2024, and Fisheye and Crucible support end 15 May 2028Atlassianaccessed 2026-10-06
  11. PrimaryJira Software 9.12 release notes: end-of-life date 29 Nov 2025; 9.12.40 released 5 Oct 2026Atlassianaccessed 2026-10-06
  12. PrimaryCrowd 7.1 release notes: 7.1.1 released 27 Nov 2025; 7.1.7 released 5 Oct 2026Atlassianaccessed 2026-10-06
  13. PrimaryBitbucket Data Center 9.4 release notes: 9.4.26 released 6 Oct 2026 (10.2 and 10.5 notes read the same way)Atlassianaccessed 2026-10-06
  14. PrimaryDownload feed: Jira Software 9.12.40 and 10.3.26 dated 2 Oct 2026, 11.3.12 dated 5 Oct 2026Atlassianaccessed 2026-10-06
  15. PrimaryConfluence documentation: installation directory versus home directory and what the start-up configuration file holds, last modified 10 Dec 2024Atlassianaccessed 2026-10-06
  16. PrimaryVulnerability management guidance, update by default: 5 days for internet-facing services, 14 days internal; published 12 Feb 2024, reviewed 1 May 2026NCSCaccessed 2026-10-06
  17. PrimaryCyber Essentials Requirements for IT Infrastructure v3.3, April 2026: 14-day security update rule, licensed and supported software definitionNCSCaccessed 2026-10-06
  18. PrimaryAlert of 27 Aug 2026 on internet-exposed systems and edge devices: inventory, vendor updates, retire end-of-life, Early WarningNCSCaccessed 2026-10-06
  19. PrimaryResearch paper of 28 Jan 2025 on forgivable and unforgivable vulnerabilities: CWE-22 mitigations and the retrofit caveatNCSCaccessed 2026-10-06
  20. PrimaryEarly Warning service: free alerts for UK organisations registered by IP address and domainNCSCaccessed 2026-10-06
  21. Reported byNews report of 6 Oct 2026, 05:20 UTC, used as the pointer: Monday email, 'Action required', filename precondition, cloud and Data Center framingThe Registeraccessed 2026-10-06
  22. Reported byThird-party tracker page repeating the CVE record's Bamboo '10.2.4 and later' figure; not relied on for any other factSecurityOnlineaccessed 2026-10-06

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

How often

Every new briefing in one email, at 7am, or at 7am, 12:30pm and 6pm. Nothing is sent when nothing is new. Unsubscribe any time.