isc.sans.edu 8 Oct 2026, 02:00 UTC

Atlassian Patches Flaw That Could Expose Files in Jira, Bitbucket and Confluence

Atlassian Patches Flaw That Could Expose Files in Jira, Bitbucket and Confluence

THE SANS podcast for 8 October 2026 reports on several ongoing security issues. A patched Atlassian vulnerability, disclosed 5 October, is being observed in honeypot traffic via proof‑of‑concept exploit strings. The flaw hinges on how Atlassian products sanitise URLs: two colons in a URL can be replaced with a slash, and the platform’s mechanism to undo this obfuscation can bypass filters that would normally block directory traversal.

Exploitation appears to allow reading arbitrary files, but attackers must know which file to read; there is no automatic directory listing. Initial probes are targeting files that are commonly present in these products, such as web[.]xml or a Bitbucket URL rewrite[.]xml. The affected products include Jira (referred to as Jera in the report), Bitbucket, and Confluence. Atlassian advises ensuring all patches are applied. The write‑up from Watchtower is cited for details on how the vulnerability functions and the nature of observed exploit strings.

The episode also notes separate incidents: hijacking of DNS for certain country‑level top‑level domains (.gh, .sl, .as) enabled attackers to obtain TLS certificates for numerous domains, including some sites hosted in those countries; Google Chrome has since blocked the affected certificates. Cisco’s NX‑OS/ Nexus switches are receiving updates addressing nine vulnerabilities, several of which are critical and affect the operation, administration and maintenance (OAM) features for VXLAN or MPLS.

Some remote‑code‑execution bugs do not require authentication but do require the attacker to inject compromised packets. Microsoft continues its policy of restricting delivery by blocking two Outlook extensions, MSIX and MSIX Bundle, associated with install packages. The report emphasises applying patches where available and monitoring for related indicators of compromise.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline