Critical OS Command Injection Vulnerability in Atlassian Bamboo Disclosed
ID: acd46b5a-ac24-5ee1-9178-314fc2be074c
STIX ID: report--acd46b5a-ac24-5ee1-9178-314fc2be074c
Feed Name: ThreatCluster
Threat Score
Atlassian disclosed two critical vulnerabilities in Bamboo Server and Data Center in its April 21, 2026 security bulletin; the most severe is CVE-2026-21571, an authenticated OS command injection (CVSS 9.4) allowing remote arbitrary command execution on affected systems. Organizations using vulnerable Bamboo versions are urged to apply the provided patches immediately to mitigate potential widespread exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
