Seven of Atlassian's 19 fixed builds for CVE-2026-21589 are on lines that leave support by 30 December
Atlassian's bulletin for CVE-2026-21589 lists 19 fixed builds across eight Data Center products; seven sit on release lines whose support ends between 3 and 30 December 2026. No exploitation is stated, and the CVE record's Crowd fix, 7.1.1, disagrees with the bulletin's 7.1.7.
By Parminder Kumar Sharma · · 17 min read

Nineteen fixed builds, and a short runway under seven of them
Atlassian's bulletin for CVE-2026-21589 names eight products and lists 19 fixed builds between them. Counted against Atlassian's own end-of-support policy page, seven of those 19 builds sit on release lines whose support ends between 3 and 30 December 2026, which is 58 to 85 days from Tuesday 6 October. Three more sit on lines that page does not list, and nine run into 2027 or 2028. These counts are derived by this site from the two Atlassian pages, and the map further down draws every one of them.
That is a fact about how long this week's patch will carry you. It does not establish that anyone is exploiting the flaw. Atlassian says its investigation found no evidence of exploitation in Cloud, says it cannot confirm whether any Data Center instance was affected, and the CISA catalogue of known exploited flaws did not list the CVE when read. Nor does the count say which files a stranger could read on your instance, how many instances are exposed to the internet, or whether the flaw has anything to do with earlier Atlassian bugs. The primaries are silent on all three, and so is this article.
State of each source when read on the morning of Tuesday 6 October 2026, UTC. Any of these can change; the times say when each was last read.
- Source
- Atlassian bulletin
- State when read
- Advisory release date 5 Oct 2026; page last modified 5 Oct 2026; no revision table on the page
- Read at (UTC)
- 05:59, same as 05:36
- Source
- Atlassian public tickets (eight)
- State when read
- All eight Published and Fixed, resolved 5 Oct between 21:04 and 21:05 UTC
- Read at (UTC)
- 05:59, same as 05:38
- Source
- CVE.org record
- State when read
- PUBLISHED 5 Oct 21:30 UTC; last updated the same minute
- Read at (UTC)
- 05:59, same as 05:35
- Source
- NVD record
- State when read
- Received, 5 Oct 22:16 UTC; no NVD or CISA-ADP score, no CWE
- Read at (UTC)
- 05:59, same as 05:35
- Source
- CISA KEV catalogue
- State when read
- Version 2026.10.04, released 4 Oct 18:52 UTC, 1,734 entries; CVE-2026-21589 not listed
- Read at (UTC)
- 05:59, same as 05:37
| Source | State when read | Read at (UTC) |
|---|---|---|
| Atlassian bulletin | Advisory release date 5 Oct 2026; page last modified 5 Oct 2026; no revision table on the page | 05:59, same as 05:36 |
| Atlassian public tickets (eight) | All eight Published and Fixed, resolved 5 Oct between 21:04 and 21:05 UTC | 05:59, same as 05:38 |
| CVE.org record | PUBLISHED 5 Oct 21:30 UTC; last updated the same minute | 05:59, same as 05:35 |
| NVD record | Received, 5 Oct 22:16 UTC; no NVD or CISA-ADP score, no CWE | 05:59, same as 05:35 |
| CISA KEV catalogue | Version 2026.10.04, released 4 Oct 18:52 UTC, 1,734 entries; CVE-2026-21589 not listed | 05:59, same as 05:37 |
What the primaries say, and what they leave out
Everything in the Stated column below is on Atlassian's bulletin, its eight public tickets, the CVE.org record or the NVD record. The Not stated column is what none of them states. Reading the second as if it were the first is how a short advisory turns into a long rumour.
Stated and not stated, from the bulletin, the eight Atlassian tickets, the CVE.org record, the NVD record and the CISA KEV catalogue, read 6 October 2026.
- Topic
- Reach
- Stated
- Unauthenticated, over the network, no user interaction. Atlassian says to restrict internet access even where instances use authentication
- Not stated
- How many instances are exposed. No scan figure is quoted here
- Topic
- What is read
- Stated
- Specific files in the web application root. The exact name and path must be known. No directory listing
- Not stated
- Which files, or which configurations put sensitive ones there
- Topic
- Exploitation
- Stated
- Cloud: patched, no evidence of exploitation found. Data Center: Atlassian cannot confirm whether instances were affected
- Not stated
- Any exploitation of Data Center, any public exploit, who found the flaw, or when
- Topic
- Scope
- Stated
- All versions of eight Data Center products
- Not stated
- Which shared component is at fault, or why eight products share it
- Topic
- Fix
- Stated
- 19 builds; release notes date 16 of them 5 Oct 2026 and Bitbucket's three 6 Oct 2026
- Not stated
- A fixed build in every supported line: 34 supported lines have none listed
- Topic
- Score
- Stated
- 9.3 Critical, CVSS 4.0, Atlassian's own assessment
- Not stated
- An NVD, CISA-ADP or CVSS 3 score, or a CWE identifier
- Topic
- Server editions
- Stated
- The CVE record lists eight Server products as affected
- Not stated
- Anything about Server in the bulletin; most have no fix listed
| Topic | Stated | Not stated |
|---|---|---|
| Reach | Unauthenticated, over the network, no user interaction. Atlassian says to restrict internet access even where instances use authentication | How many instances are exposed. No scan figure is quoted here |
| What is read | Specific files in the web application root. The exact name and path must be known. No directory listing | Which files, or which configurations put sensitive ones there |
| Exploitation | Cloud: patched, no evidence of exploitation found. Data Center: Atlassian cannot confirm whether instances were affected | Any exploitation of Data Center, any public exploit, who found the flaw, or when |
| Scope | All versions of eight Data Center products | Which shared component is at fault, or why eight products share it |
| Fix | 19 builds; release notes date 16 of them 5 Oct 2026 and Bitbucket's three 6 Oct 2026 | A fixed build in every supported line: 34 supported lines have none listed |
| Score | 9.3 Critical, CVSS 4.0, Atlassian's own assessment | An NVD, CISA-ADP or CVSS 3 score, or a CWE identifier |
| Server editions | The CVE record lists eight Server products as affected | Anything about Server in the bulletin; most have no fix listed |
Two dates are worth separating from discovery. The earliest of the eight public tickets was created on Friday 2 October at 04:26 UTC, three days and 16 hours before Atlassian resolved it, which shows the ticket existed, not when the flaw was found. The CVE identifier was reserved on 1 January 2026, 277 days before publication, which shows Atlassian reserves identifiers in advance, not that it knew of the flaw in January. By the dates on the bulletin the gap between Atlassian's email on Monday 5 October, as The Register reports it, and the bulletin is zero days.
The fix map: which line, which build, until when
Atlassian's advice is blunt: it "recommends patching to the fixed LTS version or later". Most fixed builds are on long-term-support lines. The exceptions are Bitbucket 10.5, which the policy page does not list, and three Crowd lines not marked LTS. Atlassian's security bug fix policy says critical fixes go to the latest feature release and to supported LTS releases. Support for each line runs two years from its first release, according to the policy page, last modified 22 September 2026. Put the bulletin and the policy page side by side and the runway is uneven.
Four points follow from the map, each checkable on the two Atlassian pages.
Most supported lines have no fixed build. The policy page lists 34 other release lines that are still in support after 6 October and have no fixed build in the bulletin (derived: Bamboo 3, Bitbucket 7, Confluence 5, Crowd 1, Jira Software 9, Jira Service Management 9). A Confluence 9.5 site, supported to 4 June 2027, has no fixed 9.5 build to install. It has to move to a listed build or later. Confluence 9.1 left support on 3 October, three days before this article, and is on no fix path at all.
The Jira 9.12 and Service Management 5.12 lines are an open question. The Jira Software 9.12 release notes give 29 November 2025 as that line's end-of-life date, the policy page does not list 9.12 or 5.12, and Atlassian released 9.12.40 on 5 October 2026, 310 days after the stated date. The sources do not say whether support was extended. Anyone on those lines should ask Atlassian rather than assume.
Older versions are not cleared. Each of the eight tickets says versions that have reached end of life "may also be affected". That is a statement of untested scope, not of safety.
Server editions sit outside the bulletin. The CVE record lists eight Server products as affected, and Atlassian's Server end-of-support notice put the end of support at 15 February 2024, 963 days before this bulletin. The bulletin itself covers Data Center only.
A 9.3 built on what lies downstream
Atlassian scores the flaw 9.3, Critical, with the vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H, "per our internal assessment". It adds: "This is our assessment, and you should evaluate its applicability to your own IT environment." The score is Atlassian's alone. NVD had assigned none when read, and CISA-ADP had added none.
The vector says two different things. For the vulnerable system, confidentiality impact is high and integrity and availability impacts are none, which is what a read-only flaw should score. For the subsequent systems, the three metrics SC, SI and SA are all high. This site recomputed the score from the vector with two independent open-source implementations of the CVSS 4.0 specification: both return 9.3. Setting only SC, SI and SA to none returns 8.7, High, in both. So the whole step from High to Critical rests on the assumption that a file read leads to harm elsewhere. Atlassian's own caveat points the same way: "In some configurations, there may be sensitive files present that increase your risk."
That is not a criticism. A vendor cannot see your web root, so it plausibly scores a worst reasonable case; the bulletin does not explain its choice of values. The point is what the number cannot do: it cannot tell you which case you are in. Both 9.3 and 8.7 are above the 7.0 line that Cyber Essentials applies to CVSS 3 scores, though the versions differ, so the arithmetic changes the label and not the clock. The site has looked before at how two scoring versions of one flaw land in different bands.
The friendly-name fallacy runs both ways. "File access" sounds milder than remote code execution, and The Register is right that, in Atlassian's words, exploitation "requires prior knowledge of the target file's exact name and path" and directories cannot be listed. Those are stated preconditions and are true to the primary. What the primaries do not say is how hard the name and path are to know. This is judgement, labelled as such: Atlassian publishes its software, so the layout of a default install can be learned by anyone, and the precondition raises the bar for files an administrator added, not for files every install has.
Two further cautions on labels. The CVE record's problem type is free text, "Path Traversal (Arbitrary Read/Write)", with no CWE identifier, while the vector scores no integrity impact on the vulnerable system. Treat the flaw as read until Atlassian says otherwise. And Atlassian's block rule and detection advice both concern two dots next to a path separator, which suggests, as inference only, that the fault is in how the request path is handled. The bulletin names no component.
For context, not as a link: CISA's catalogue holds 13 Atlassian entries, three of them described as path traversal or arbitrary file read (CVE-2019-3398, CVE-2021-26085 and CVE-2021-26086). The class has been exploited in Atlassian products before. Nothing in the primaries connects any of those flaws to this one.
Where Atlassian's own records disagree
The bulletin is Atlassian's page. The CVE record is Atlassian's submission to the CVE programme. Both appeared on 5 October, the tickets and the record about 25 minutes apart, and they do not agree. For anyone who patches from a vulnerability scanner, a ticketing feed or a CVE-record parser, the record is the version they will see.
Disagreements among Atlassian's bulletin, its public tickets, its release notes, its download feed and its CVE.org record, read 6 October 2026.
- Item
- Crowd 7.1 fixed build
- One Atlassian source says
- Bulletin and the ticket's fix-version field: 7.1.7
- Another says
- CVE record: 7.1.1, released 27 Nov 2025, 312 days before the bulletin. Ticket text: 7.1.6, which the same ticket lists as affected
- Item
- Bamboo 10.2 fixed build
- One Atlassian source says
- Bulletin and CVE description: 10.2.24
- Another says
- CVE affected-version data: 10.2.4 and later. One third-party tracker page repeats it
- Item
- Release dates of the fixed builds
- One Atlassian source says
- Release notes: 5 Oct 2026 for 16 builds, 6 Oct for Bitbucket's three
- Another says
- Download feed: 2 Oct for two Jira builds, 6 Oct for four Crowd builds. Ticket version data differs again
- Item
- How far back
- One Atlassian source says
- Bulletin: all versions
- Another says
- CVE record: introduced in builds from Jira Software 7.1.0 and Service Management 3.1.0 (10 Feb 2016) to Bamboo 7.0.1 (10 Mar 2020); nothing for Crucible or Fisheye
- Item
- Editions
- One Atlassian source says
- Bulletin: Data Center only
- Another says
- CVE record: eight Server products also affected
- Item
- What the flaw allows
- One Atlassian source says
- Bulletin and vector: file access; no integrity impact on the vulnerable system
- Another says
- CVE problem type: Read/Write
| Item | One Atlassian source says | Another says |
|---|---|---|
| Crowd 7.1 fixed build | Bulletin and the ticket's fix-version field: 7.1.7 | CVE record: 7.1.1, released 27 Nov 2025, 312 days before the bulletin. Ticket text: 7.1.6, which the same ticket lists as affected |
| Bamboo 10.2 fixed build | Bulletin and CVE description: 10.2.24 | CVE affected-version data: 10.2.4 and later. One third-party tracker page repeats it |
| Release dates of the fixed builds | Release notes: 5 Oct 2026 for 16 builds, 6 Oct for Bitbucket's three | Download feed: 2 Oct for two Jira builds, 6 Oct for four Crowd builds. Ticket version data differs again |
| How far back | Bulletin: all versions | CVE record: introduced in builds from Jira Software 7.1.0 and Service Management 3.1.0 (10 Feb 2016) to Bamboo 7.0.1 (10 Mar 2020); nothing for Crucible or Fisheye |
| Editions | Bulletin: Data Center only | CVE record: eight Server products also affected |
| What the flaw allows | Bulletin and vector: file access; no integrity impact on the vulnerable system | CVE problem type: Read/Write |
The practical rule is short. Use the bulletin's build numbers, confirm the build you install is at or above the number for your line, and check the release notes page for that line. Do not let a scanner mark Crowd 7.1.1 or Bamboo 10.2.4 as fixed. The oldest line the record names was released more than ten and a half years before disclosure (3,890 days from 10 February 2016 to 5 October 2026, derived), but the record's start versions are the CVE submission's claim, not the bulletin's.
What discontinuing Data Center does and does not cover
The Register says Atlassian "decided to discontinue its datacenter software", and a reader could take from that one end date for all eight affected products. Atlassian's own end-of-life page says something narrower, and this article follows the vendor page.
Data Center end-of-life dates for the eight affected products, from Atlassian's end-of-life page and support pages read 6 October 2026. Day counts derived from 6 October 2026.
- Product
- Jira Software, Jira Service Management, Confluence and Crowd Data Center
- Atlassian's stated date
- End of life 28 Mar 2029 at 23:59 PST, then read-only
- Days
- 904
- Product
- Bitbucket Data Center and Bamboo Data Center
- Atlassian's stated date
- "Will not end of life", via a Bitbucket Hybrid License
- Days
- no date
- Product
- Crucible and Fisheye
- Atlassian's stated date
- Support ends 15 May 2028; no new sales since 13 May 2025
- Days
- 587
| Product | Atlassian's stated date | Days |
|---|---|---|
| Jira Software, Jira Service Management, Confluence and Crowd Data Center | End of life 28 Mar 2029 at 23:59 PST, then read-only | 904 |
| Bitbucket Data Center and Bamboo Data Center | "Will not end of life", via a Bitbucket Hybrid License | no date |
| Crucible and Fisheye | Support ends 15 May 2028; no new sales since 13 May 2025 | 587 |
Through 28 March 2029 Atlassian promises technical support and security fixes for critical vulnerabilities for the affected Data Center products, and new customers have been unable to buy Data Center since 30 March 2026, 190 days ago. Existing customers can expand until 30 March 2028. After the end date the instance is read-only, and Atlassian says: "We strongly advise against keeping your product running in a read-only mode while connected to the internet."
Two UK points. First, Cyber Essentials requires in-scope software to be licensed and supported, and defines support as a vendor commitment with a stated end date; Atlassian's dates are those dates. Second, for bodies on an April to March financial year, the end-of-life date, 28 March 2029, is three days before that year closes on 31 March 2029, and the last day to expand, 30 March 2028, is one day before the year closing on 31 March 2028. That is judgement, not a source claim: a migration first funded in the 2028 to 2029 year starts in the last year of support.
The UK clocks, and what the NCSC does and does not say
Two published clocks apply to a self-hosted instance, and both start at release. The bulletin is dated Monday 5 October, and the release notes date 16 of the 19 fixed builds to the same day; Bitbucket's three say 6 October, a day later, with no time zone given.
Patching clocks from a 5 October 2026 release. NCSC vulnerability management guidance (published 12 Feb 2024, reviewed 1 May 2026, version 2.1) and Cyber Essentials Requirements for IT Infrastructure v3.3 (April 2026), read 6 October 2026.
- Clock
- 5 days, internet-facing services and software
- Source
- NCSC best practice
- Counted from 5 Oct
- Saturday 10 Oct 2026
- Clock
- 14 days, vendor-rated critical or high, or CVSS 3 base 7 or above
- Source
- Cyber Essentials v3.3
- Counted from 5 Oct
- Monday 19 Oct 2026
- Clock
- 14 days, internal and air-gapped services
- Source
- NCSC best practice
- Counted from 5 Oct
- Monday 19 Oct 2026
| Clock | Source | Counted from 5 Oct |
|---|---|---|
| 5 days, internet-facing services and software | NCSC best practice | Saturday 10 Oct 2026 |
| 14 days, vendor-rated critical or high, or CVSS 3 base 7 or above | Cyber Essentials v3.3 | Monday 19 Oct 2026 |
| 14 days, internal and air-gapped services | NCSC best practice | Monday 19 Oct 2026 |
Cyber Essentials counts "critical or high risk" by a CVSS 3 base score of 7 or more, or by the vendor's own wording. Atlassian publishes only a CVSS 4.0 vector and calls the flaw Critical, so the vendor-wording route applies; that is this site's reading. If the 2 October date in Atlassian's download feed for two Jira builds is the one that counts, the 14 days end on 16 October. The NCSC guidance also says that for an actively exploited internet-facing flaw you should check for compromise before updating. Exploitation is not established here, so that rule is not triggered, but the logs should be copied before any node restarts.
What the NCSC has said about this flaw: nothing found. Keyword searches of ncsc.gov.uk at about 06:57 BST on 6 October returned six items for "Atlassian" and three for "Confluence", all general guidance or research, and nothing about this CVE. Nothing found is specific to collaboration or developer tooling either. The closest guidance is general. The NCSC's 27 August 2026 alert on internet-exposed systems is operational-technology focused, but tells other organisations to keep an accurate inventory of internet-facing systems, apply vendor updates promptly, retire end-of-life equipment and register for the free Early Warning service. Early Warning works from the IP addresses and domains you register; whether it will flag this flaw is not stated. The NCSC's January 2025 paper on 'unforgivable' vulnerabilities lists CWE-22 path traversal and scores input validation, one of its mitigations, as easy, but says the scoring assumes mitigations are built in from the start and not retrofitted. With no code-level cause published, this article makes no forgivable or unforgivable call.
Who is exposed in the UK is not in the sources. There is no UK install count. Atlassian's own end-of-life page says "source code and CI/CD pipelines are mission-critical" and some organisations "may need to keep them self-managed". Judgement: that profile fits public bodies, universities, NHS trusts and defence suppliers that keep source code or tickets in-house, but the sources name no sector. The first item in Atlassian's shared-responsibility list is "Operating Atlassian software on private networks".
What sits in a web root is the open question. The bulletin does not list files. Atlassian's Confluence documentation puts the start-up configuration file, which holds database connection settings, in the home directory and not the installation directory. In that layout those settings are not under the web application. "In some configurations" is then the risk: a layout where someone has put configuration, backups, exports or scripts under the application directory. Whether yours is one of them is a check, not a guess.
What to do, in the order worth doing it
Take this with you
Order of work
- Find every Atlassian instance and version: Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye, including test, staging, inherited and old Server-era installs. Use licence records, DNS and reverse proxy configuration, and ask who runs Crucible or Fisheye, which are easy to forget.
- Take each internet-facing instance off the internet, or put it behind a VPN or single sign-on at the proxy, until it is patched. Atlassian says this applies even where instances use authentication.
- For anything you cannot patch today, apply the block rule in the bulletin for your product, at the proxy or firewall, in Tomcat or in Bitbucket's rewrite file. Back up first, test it, and keep the patch date.
- Patch to a build at or above the bulletin's number for your line, or move to a newer listed line. If your line has no fixed build, plan the move now. Use the bulletin's numbers, not the CVE record's, for Crowd and Bamboo.
- Before restarting any node, copy web server, proxy and application access logs off the host.
- Search the logs for as far back as you keep them. Atlassian's own advice is to decode each request line, up to two passes, and look for two dots next to a path separator, or to search raw lines with the bulletin's pattern. Look for successful responses as well as attempts, and for one source sending many differently shaped requests. No start date for any exploitation is stated, so the window is every retained log.
- Rotate any secret that sat in a file under a web application directory, or that you cannot show did not. This is judgement: Atlassian does not tell you to rotate anything, and rotating costs less than not knowing.
- Put the next upgrade in the plan: any instance patched to a line that ends support in December 2026 already has a date. Cyber Essentials needs supported software.
- Register the organisation for NCSC Early Warning, and subscribe a named person to Atlassian's advisory emails so the next notice has an owner.
A block rule is a stopgap, not a fix. The site's earlier briefing One letter past the WAF covers what happens when a rule matches one spelling of a path and the attacker uses another. Atlassian's pattern is written to cover encoded forms, but only a patched build removes the dependence on any rule.
The question the score cannot answer
Atlassian has done the part a vendor can do: it published fixed builds, a block rule, detection advice and a plain statement that it cannot confirm whether any instance was affected. The score, the clocks and the end-of-life dates all assume something the sources cannot see, which is what sits under your web root and who last checked.
So the question is not whether this flaw is a 9.3 or an 8.7. For each Atlassian instance you run, can you name the one file under its web application directory that you would least want a stranger to read, and show who checked that it is not there?
Key facts
Sources
- PrimarySecurity bulletin for CVE-2026-21589, advisory release date 5 Oct 2026: affected products, fixed versions, CVSS 4.0 vector, mitigations, detection advice, Cloud statementAtlassianaccessed 2026-10-06
- PrimaryCVE.org record: published 5 Oct 2026 21:30 UTC, affected and unaffected version data, introduced-in versions, problem type, 4.0 vectorCVE Program (CNA: Atlassian)accessed 2026-10-06
- PrimaryNVD record: status Received, published 5 Oct 2026 22:16 UTC, Atlassian's score only, no CWE, no CISA-ADP dataNIST National Vulnerability Databaseaccessed 2026-10-06
- PrimaryKnown Exploited Vulnerabilities catalogue, version 2026.10.04, 1,734 entries; CVE-2026-21589 absent; 13 Atlassian entriesCISAaccessed 2026-10-06
- PrimaryPublic ticket for Crowd: fix-version field 7.1.7, description table 7.1.6, creation and resolution times; the seven sibling tickets were read the same wayAtlassianaccessed 2026-10-06
- PrimaryPublic ticket for Confluence: earliest created of the eight, 2 Oct 2026 04:26 UTC; end-of-life versions may also be affectedAtlassianaccessed 2026-10-06
- PrimaryData Center end of life: 28 Mar 2029 for Jira Software, Jira Service Management, Confluence and Crowd; Bitbucket and Bamboo not ending; sales and support datesAtlassianaccessed 2026-10-06
- PrimaryAtlassian End of Support Policy, last modified 22 Sep 2026: end-of-support date of every release line; Fisheye and Crucible support to 15 May 2028Atlassianaccessed 2026-10-06
- PrimarySecurity Bug Fix Policy: critical fixes to the latest feature release and supported LTS releases; shared responsibility listAtlassianaccessed 2026-10-06
- PrimaryServer end of support: 15 Feb 2024, and Fisheye and Crucible support end 15 May 2028Atlassianaccessed 2026-10-06
- PrimaryJira Software 9.12 release notes: end-of-life date 29 Nov 2025; 9.12.40 released 5 Oct 2026Atlassianaccessed 2026-10-06
- PrimaryCrowd 7.1 release notes: 7.1.1 released 27 Nov 2025; 7.1.7 released 5 Oct 2026Atlassianaccessed 2026-10-06
- PrimaryBitbucket Data Center 9.4 release notes: 9.4.26 released 6 Oct 2026 (10.2 and 10.5 notes read the same way)Atlassianaccessed 2026-10-06
- PrimaryDownload feed: Jira Software 9.12.40 and 10.3.26 dated 2 Oct 2026, 11.3.12 dated 5 Oct 2026Atlassianaccessed 2026-10-06
- PrimaryConfluence documentation: installation directory versus home directory and what the start-up configuration file holds, last modified 10 Dec 2024Atlassianaccessed 2026-10-06
- PrimaryVulnerability management guidance, update by default: 5 days for internet-facing services, 14 days internal; published 12 Feb 2024, reviewed 1 May 2026NCSCaccessed 2026-10-06
- PrimaryCyber Essentials Requirements for IT Infrastructure v3.3, April 2026: 14-day security update rule, licensed and supported software definitionNCSCaccessed 2026-10-06
- PrimaryAlert of 27 Aug 2026 on internet-exposed systems and edge devices: inventory, vendor updates, retire end-of-life, Early WarningNCSCaccessed 2026-10-06
- PrimaryResearch paper of 28 Jan 2025 on forgivable and unforgivable vulnerabilities: CWE-22 mitigations and the retrofit caveatNCSCaccessed 2026-10-06
- PrimaryEarly Warning service: free alerts for UK organisations registered by IP address and domainNCSCaccessed 2026-10-06
- Reported byNews report of 6 Oct 2026, 05:20 UTC, used as the pointer: Monday email, 'Action required', filename precondition, cloud and Data Center framingThe Registeraccessed 2026-10-06
- Reported byThird-party tracker page repeating the CVE record's Bamboo '10.2.4 and later' figure; not relied on for any other factSecurityOnlineaccessed 2026-10-06


