Atlassian has told its users to patch its datacenter products, pronto, to prevent attackers accessing their files. The Australian collaborationware company on Monday sent users an email that opens with the words “Action required” and points to a security bulletin that explains CVE-2026-21589. The 9.3-rated arbitrary file access vulnerability is present in the datacenter versions of its Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible, and Fisheye products. Atlassian says the vulnerability “allows an unauthenticated attacker to access specific files within the web application root directory in affected versions.” That’s scary because Atlassian warns “In some configurations, there may be sensitive files present that increase your risk.” There’s also some good news in that attackers must know the exact filename and path to exploit the vulnerability, and the mess doesn’t allow anyone to see the contents of a directory. Another piece of good news is that Atlassian has updated its products – so users only need to find a change window in which to upgrade to a safe version of their software. Atlassian advised those who can’t patch ASAP to remove their instances from the internet, if possible. “Instances accessible to the public internet, including those with user authentication, should be restricted from external network access until you can take action,” the company warned. Its advisory also includes mitigations and advice on how to determine if your instances need the fix. Users who made the move from datacenter products to the Atlassian cloud have nothing to do, as Atlassian fixed the flaws in its own SaaS. That state of affairs rather vindicates Atlassian’s 2020 decision to stop developing its low-end server products and require users to shift into its cloud, and last year’s sequel in which it decided to discontinue its datacenter software, too. Atlassian admitted it hasn’t made that migration easy, because it somehow released a lift and shift tool that was worse than an earlier version. In March 2026, Atlassian axed ten percent of staff. The company’s share price was on a year-long slide at the time, as pundits suggested it might fall victim to the SaaSPocalypse, a theory that AI would replace business software. The price of Atlassian scrip has tripled since then, suggesting investors are more confident the company’s plan to use AI to power workflows represents a moat LLMs cannot cross. ®
Linux KVM, the hypervisor favoured by hyperscale clouds, apparently has a full VM escape bug. That nasty news came from security researcher Paulos Yibelo, who on X shared a screenshot of a bug bounty award he won for discovering what he described as “Full VM escape zeroday (guest>host root in industry standard hypervisors)!” The bug bounty Yibelo participated in is run by Vercel, a company that provides MicroVMs as sandboxes for AI agents to work inside. The company’s Sandbox uses Firecracker MicroVMs, a technology created by AWS, which relies on Linux KVM – the kernel level hypervisor in Linux. Vercel CEO Guillermo Rauch named KVM as the hypervisor identified by Yibelo. “We’ve confirmed a KVM 0day through our Vercel Sandbox bounty program. Affecting the industry’s gold standard solution for Linux virtualization,” he wrote. And that’s all the info that has made it into the public view at this time. The Register can find no chat on relevant mailing lists. We have asked Rauch and Yibelo for additional details. Hopefully, we don’t hear from either of them for days or weeks, for two reasons. One is that guest-host escapes are the nightmare virtualization scenario because they mean whoever runs a guest VM could take over an entire server, and perhaps gain the ability to control other guests. The other is that KVM is astoundingly prevalent: AWS and Google both use it to power their public clouds. Enterprise virtualization players Nutanix, HPE, and Proxmox also rely on KVM. And of course KVM is also in Firecracker, which is open source and could therefore be running in all sorts of places. Whatever Yibelo discovered therefore very much needs a responsible disclosure process, because if hints about the flaw emerge it could allow attackers to do a lot of damage. Once a fix is found, the next question is whether implementing it will require disruption or downtime. It’s possible to hot-patch KVM, and to migrate live VMs from vulnerable hosts to machines running a patched version of Linux. Hopefully those techniques will work. This might be the second nasty bug discovered in KVM this year, after the so-called Januscape flaw. Beyond the potential risks this bug created, observers have suggested the potential seriousness of the flaw means Yibelo’s reward should exceed the $50,000 available under Vercel’s bug bounty program. ®
The attackers just keep coming after Citrix NetScaler appliances, as both the feds and private security researchers warn that someone found - and has already exploited - yet another Citrix bug before it had a patch. This latest vulnerability, tracked as CVE-2026-88779, is a memory overflow bug that leads to denial of service attacks. It only affects NetScaler ADC and Gateway appliances configured as a SAML (Security Assertion Markup Language) service provider or identity provider, used for single sign-on authentication. Late Friday, amid exploitation reports, Citrix confirmed that it was investigating a “newly observed issue related to SAML authentication in customer-managed NetScaler deployments.” By Saturday night, the vendor released a security advisory for NetScaler ADC and NetScaler Gateway with patches, urging vulnerable customers to “install the relevant updated versions as soon as possible.” Citrix also posted a blog about the vulnerability, confirming that it has observed targeted attacks on unmitigated NetScaler deployments that can lead to denial of service. Citrix did not answer our questions about CVE-2026-88779 - including how many instances have been affected and what attackers are doing after exploiting the bug - but urged customers to "quickly apply" the fix to NetScaler instances. "We were recently alerted to a new issue that affects service availability for some NetScaler deployments," a Citrix spokesperson told The Register. "After we were alerted to this issue we immediately developed and published a mitigation while concurrently developing, testing and deploying a fix." On Sunday, the US Cybersecurity and Infrastructure Security Agency (CISA) confirmed CVE-2026-88779 was under active exploitation and ordered federal agencies to patch the bug by Wednesday. While the new vulnerability is not technically related to the earlier eight CVEs finally disclosed by Citrix on September 27 - weeks after miscreants began abusing two of these security holes (CVE-2026-88772 and CVE-2026-88771) - watchTowr researchers told us they suspect it has been used to purposefully crash machines, making exploitation of CVE-2026-88771 faster. “This vulnerability is incredibly simple to trigger, with a single specially crafted request being all that is needed to knock an appliance offline,” watchTowr’s head of threat intelligence, Jake Knott, told The Register. “Exploitation is already occurring in the wild, and disrupting an authentication gateway can prevent legitimate users from accessing the services behind it.” WatchTowr reproduced the vulnerability on Friday, and Citrix credited the attack-surface management company along with Bishop Fox with helping it address the issue. “Citrix provides an indicator-of-compromise script that teams can run to check exposed appliances for signs of compromise, though a clean result is not definitive proof,” Knott said. “Security teams should prioritize appliances configured as a Gateway or AAA virtual server with SAML authentication enabled, and affected organizations should apply the fixed build or Citrix’s interim mitigation if an immediate upgrade is not possible.”®