top of page

Atlassian CVE-2026-21589: LeakIX Took Inventory of Us Two Days Before the PoC. The Exploit Never Came. CISA Still Hasn't Listed It.

Writer: Patrick Duggan
Patrick Duggan
7 hours ago
4 min read

Atlassian patched CVE-2026-21589 on October 5. watchTowr published a full technical breakdown and a working proof of concept on October 6. By late October 7, attackers were trying it against real servers. As of this morning, October 8, CISA has not added it to the Known Exploited Vulnerabilities catalog. In fact CISA has added nothing since October 4. This post is about the gap between those dates, and about what our own edge saw while it opened, measured properly this time.



The bug


Credit for the research belongs to watchTowr Labs. Atlassian found and disclosed the flaw itself and shipped fixes for all eight affected self-managed products: Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo, Crowd, Crucible and Fisheye. It scores 9.3.


It is a path traversal in how these products serve web resources. Double-colon sequences turn into path separators during request processing, so a request that looks like it is asking for a static asset can walk into the application's own folder. No login is needed. The limit is that the attacker has to know the exact name and location of the file they want, because the bug cannot list a folder.


That limit matters less than it sounds, because the valuable files are in the same place on every install. Help Net Security, citing Previdian's honeypot network, reports the first attempts asked for two of them: WEB-INF/web.xml, the application's configuration, and WEB-INF/classes/crowd.properties, which holds an application credential in plain text. A credential that lets one Atlassian product talk to Crowd is a key to user management.





What our edge saw, and why we got it wrong the first time


We run no Atlassian software. Anything aimed at it that reaches us is a scanner spraying the internet, and we block at the edge, so the evidence lives in our edge records rather than in a honeypot behind them. Our first look this morning missed that. The origin-side honeypot showed zero Atlassian requests, and searching our edge block log for the exploit paths also returned zero. Both zeros were false. The origin honeypot only sees traffic the edge lets through. The block log stores the request path but our search index does not cover that field, so every path search comes back empty.


So we built a tool that reads every edge block and every edge decoy hit directly and reports how many it read, then ran it. Here is what came back, against 19,052 edge blocks and 47,962 edge decoy hits since September 1.


Before the PoC: on October 4 at 04:59 UTC and October 5 at 15:12 UTC, 15 DigitalOcean addresses sent 17 requests for /s/[build-id]/_/;/META-INF/maven/com.atlassian.jira/jira-webapp-dist/pom.properties. That path uses an older semicolon trick to read the file where Jira records its own version number. The user agent was l9scan/2.0, which is LeakIX, a service that indexes exposed software and misconfigurations across the internet. Across those two days, the same scanner sent us 247 requests from 22 addresses, on all sorts of paths. That is an inventory sweep: it asks what you run, and it reads nothing sensitive.


After the PoC: nothing. No request for web.xml. No request for crowd.properties. No hit on any of the path fingerprints we extracted from the eight public PoC repositories our harvester indexed between October 6 at 18:01 UTC and this morning. The only double-colon requests we blocked were a different trick: .env files with ::$DATA appended, a Windows file-stream suffix that credential sprayers have used for years. They have nothing to do with this bug.





What that does and does not mean


It does not mean nobody is exploiting this. Previdian saw attempts, and an operator going after Atlassian servers has no reason to spend requests on a site that does not run Atlassian. Our edge is a view of the internet's background spraying, not of targeted attacks.


It also does not give us a lead. The LeakIX sweep came before the PoC, but it was asking for version numbers, which scanners do every week. Calling that early detection of this exploit would be the kind of claim we have had to correct before. The honest reading is narrower and still useful: the inventory scanners already knew which Jira builds were where before the exploit was public. When the PoC lands, the list of targets already exists. That is why the hours between a PoC and the first attempts keep shrinking.


One more caveat about our own coverage. Our edge decoys answer only on paths we have set traps for: config files, WordPress, cloud credentials and similar. There is no Atlassian decoy, so Atlassian probes can only show up as blocks. That is a gap we know about, the same one we described for NetScaler in our post on the four NetScaler KEV entries.



The KEV clock is running


The catalog's last addition was CVE-2026-88779, NetScaler, on October 4. Its version is 2026.10.04 with 1,734 entries, and our copy matches it exactly. Since then a 9.3 in eight Atlassian products has gone from patch to public PoC to observed attempts in about two days. We will record how many days CISA takes to list CVE-2026-21589. If your patch priority list comes only from KEV, this is the week it lags.



What to do


If you run any of the eight products on your own servers, apply Atlassian's fixed versions now. Then assume crowd.properties may have been read if the server was reachable from the internet after October 6, and rotate the Crowd application credential it contains. Check your web server logs for requests containing double colons or for WEB-INF paths in the static-resource URLs. The advisory covers the self-managed Data Center and Server products; check Atlassian's advisory for anything else you run.


If you defend a network and want to know what scanners already know about you, LeakIX publishes its findings. Look yourself up before someone else does.


Was this useful? Rate this post. The widget is at the bottom of the page, and we read every response.




Every indicator in this post is in the feed. Free.

1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.



Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=atlassian-cve-2026-21589-leakix-inventory-before-poc-edge-saw-no-exploit



Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page