Critical Bamboo Data Center and Server Vulnerability Enables Command Injection Attacks
ID: 857b7fe4-c0e0-551a-bcc9-f2276e40ea34
STIX ID: report--857b7fe4-c0e0-551a-bcc9-f2276e40ea34
Feed Name: Cyber Press
Atlassian disclosed CVE-2026-21571, a critical OS command injection in Bamboo Data Center and Server (CVSS 9.4) that can be exploited remotely with low authentication and low complexity; multiple versions are affected and Atlassian has released patched releases (e.g., Bamboo Data Center 12.1.6 LTS, 10.2.18 LTS, 9.6.25). The flaw risks unauthorized access, CI/CD pipeline compromise, and potential supply-chain attacks, and organizations are urged to apply updates or follow Atlassian's mitigation guidance and audit their deployments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
