Atlassian’s Eight Open Drawers
CVE-2026-21589 lets unauthenticated attackers who know an exact path read files from eight self-hosted Atlassian products; watchTowr reports exploitation. Patch fixed releases, restrict public access until updated, and review access logs.