ATLASSIAN has addressed two high-severity vulnerabilities in its self-hosted products. The first, CVE-2026-21580, is a stored XSS vulnerability in Confluence, scoring a CVSS of 9.3, allowing unauthenticated attackers to execute code in users' browsers, potentially leading to privilege escalation. The second flaw, CVE-2026-21582, impacts Jira Service Management with a score of 8.8, allowing unauthenticated users to impersonate others. Both vulnerabilities have patches available, and Atlassian has reported no confirmed exploitations in the wild.
Atlassian fixes XSS, impersonation bugs in Confluence, Jira
CyberSIXT Evidence Panel
Article by CyberSIXT