Check your Atlassian product and installed version against the fixed-release table below. Atlassian’s October 5, 2026 advisory says all versions of the listed products before their applicable fixes are affected by CVE-2026-21589, a critical arbitrary file access vulnerability. You do not need to test for a live exploit to establish whether a version is in scope.
Which Atlassian products are affected?
The advisory covers Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian describes the flaw as unauthenticated access to specific files in the web application root. An attacker must already know the exact file name and path; the vulnerability does not provide directory listing or file enumeration.
Atlassian rates CVE-2026-21589 Critical, with a CVSS score of 9.3 from its internal assessment. The advisory does not report a prevalence statistic or exploitation count. Read Atlassian’s CVE-2026-21589 advisory.
How to check your product and version
- Inventory every deployment and cluster node, recording the product name, installed version, and whether it is a Data Center instance. Include Crucible and Fisheye if you operate them.
- Find the matching product row in the table below. Compare your installed version with the fixed release applicable to your product and release line.
- If your version is earlier than the applicable fix, it is within the affected scope described by Atlassian. Plan an upgrade to a listed fixed release or later, checking the product’s release notes and support requirements first.
These are the fixed versions named in Atlassian’s October 5, 2026 advisory. They are not necessarily the latest available releases, and the advisory does not rank the alternatives.
Recommended Free Tools
#1 Best Overall
- Passwordless Login with Fingerprint Security: imKey Pass S6 is a FIDO2-certified hardware security key designed for passwordless authentication. Simply plug in the device and verify with your fingerprint to securely sign in to supported services. This physical passkey protects your accounts from phishing, password leaks, and unauthorized access.
- Strong Two-Factor Authentication (2FA) Protection: Supports FIDO2 and FIDO U2F protocols, allowing you to enable strong hardware-based 2FA on popular platforms including Google, GitHub, Amazon, X and Binance. Replace SMS codes or authenticator apps with a safer hardware login method.
- Fingerprint + PIN Dual Protection: Built-in fingerprint sensor provides fast local identity verification, while an optional PIN adds an additional layer of protection. Even if the device is lost, unauthorized users cannot access your accounts without biometric verification.
- Universal Compatibility with Modern Systems: Works with Windows, macOS, and major browsers including Chrome, Edge, Safari, and Firefox that support WebAuthn and Passkey authentication standards. A single key can secure multiple online accounts and services.
- Compact, Durable & Easy to use: Designed as a portable USB-C security key that easily attaches to your keychain. No battery, no charging, and no software installation required. Just plug in and authenticate with a fingerprint.
| Product | Fixed versions listed |
|---|---|
| Bitbucket Data Center | 9.4.26, 10.2.8, 10.5.1 |
| Confluence Data Center | 9.2.26, 10.2.19 |
| Jira Service Management Data Center | 5.12.40, 10.3.26, 11.3.12 |
| Jira Software Data Center | 9.12.40, 10.3.26, 11.3.12 |
| Bamboo Data Center | 10.2.24, 12.1.12 |
| Crowd Data Center | 6.3.7, 7.0.3, 7.1.7, 7.2.4 |
| Crucible | 4.9.15 |
| Fisheye | 4.9.15 |
What to do if your installation is affected
Upgrade as the primary fix
Upgrade each affected installation to a fixed version listed for that product or a later version, following the relevant release notes. For clustered deployments, include every affected installation and relevant node in the upgrade plan; updating only one node can leave the deployment incompletely addressed. Select among listed releases based on compatibility, supported release or LTS path, maintenance requirements, and the time needed to upgrade.
Reduce exposure while an upgrade is pending
If you cannot patch immediately, Atlassian recommends restricting external access where possible, including taking a publicly accessible instance off the internet. This applies even when the instance requires users to authenticate.
Rank #2
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.
The advisory also describes temporary mitigations: a traversal-pattern block at a web application firewall (WAF) or proxy; a Tomcat RewriteValve configuration for Confluence, Jira Service Management, Jira Software, Bamboo, and Crowd; and a urlrewrite.xml rule for Bitbucket. These procedures are product- and infrastructure-specific. Back up relevant files and test the rule, including URL-encoded patterns, and follow the complete instructions in Atlassian’s advisory rather than copying a rule without its context.
How to investigate possible access attempts
Review access logs for requests that may contain path traversal patterns. Atlassian advises URL-decoding each request line up to two passes and looking for .. immediately adjacent to /, \, or ::. You can also search raw lines with the regular expression provided in the advisory.
Rank #3
- Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
- FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
- Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
- Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.
A matching request is an indicator to investigate, not proof that the vulnerability was successfully exploited or that a system was compromised. Atlassian says it cannot confirm whether customer instances have been affected. Ask your local security team to assess suspicious activity and determine whether further incident-response steps are needed.
Quick Recap
Best Value
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Rank #4
- USB-C or tap via NFC for easy authentication on any compatible device. No drivers needed; optional Kensington software available for advanced management features.
- Works across Windows, macOS, iOS, Android, ChromeOS, and supports Passkeys and Apple ID.
- Slim, keychain-ready form for easy carry and on-the-go authentication
- IP68-rated for dependable performance
- FIDO CTAP 2.1 for enhanced security features (e.g. resident credentials, Passkey support) and backwards compatibility with CTAP 2. FIDO2 L2 certified security for phishing resistant protection against identity theft and unauthorized access.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

