Monday afternoon Atlassian put out an out-of-cycle critical security advisory for the editions of its products that companies run on their own servers: Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo, and Crowd Data Center, plus Crucible and Fisheye. Someone with no login can read certain files inside the application’s folder on the server, if they already know each file’s exact name and location. Atlassian says some setups keep sensitive files there. The flaw is CVE-2026-21589, rated 9.3 in Atlassian’s own assessment. Atlassian says its Cloud products are already patched and it found no evidence of exploitation there. It has not reported attacks on self-hosted servers, but says it cannot confirm whether a given server was already hit. Atlassian’s regular bulletins come on the third Tuesday of the month; this one came early.

If any of those run on your own servers, put the upgrade at the top of the change list. Atlassian’s advisory names these fixed versions; install the one on your line or newer: Jira Software 9.12.40, 10.3.26, or 11.3.12; Jira Service Management 5.12.40, 10.3.26, or 11.3.12; Confluence 9.2.26 or 10.2.19; Bitbucket 9.4.26, 10.2.8, or 10.5.1; Bamboo 10.2.24 or 12.1.12; Crowd 6.3.7, 7.0.3, 7.1.7, or 7.2.4; Crucible and Fisheye 4.9.15. Some other Atlassian records show different Crowd and Bamboo numbers; go by the advisory. Until the upgrade is on, take the server off the public internet — Atlassian says that applies even if it asks for a login — or put one of Atlassian’s temporary blocking rules in front of it, which Atlassian says is not a replacement for patching. Ask whoever runs the server to check its access logs the way the advisory describes. The fix list covers the Data Center editions; if you still run an older Server edition, ask Atlassian support. Teams that only use Atlassian Cloud have nothing to do, and employees do not need to change passwords because of this.

A separate fix for home and office PCs. Apache OpenOffice said Friday that a booby-trapped spreadsheet can run code on the computer when it is opened, if Java support is turned on in the program. Every version through 4.1.16 is affected and there is no fix yet; 4.1.17 is still in testing, with no release date announced. Until it ships, OpenOffice’s advisory says to go to Tools → Options → OpenOffice → Java (OpenOffice → Preferences → OpenOffice → Java on a Mac) and untick Use a Java runtime environment, and to avoid opening files from people you don’t know. LibreOffice disclosed the same kind of flaw Monday, but the fix was already in 26.2.5 and 26.8.0, which shipped July 23 and August 26. In LibreOffice, check Help → About: 26.2.5 or newer on the 26.2 line, or 26.8.0 or newer, means you are covered; anything older, update. A proof of concept is public, but no attacks have been reported. People who use other office programs have nothing to change here.