logo

Critical OS Command Injection Vulnerability in Atlassian Bamboo Disclosed

ID: acd46b5a-ac24-5ee1-9178-314fc2be074c

STIX ID: report--acd46b5a-ac24-5ee1-9178-314fc2be074c

Feed Name: ThreatCluster

Threat Score
76/100

Date Published: 2026-04-22

Date Updated: 2026-04-22

...
...

Atlassian disclosed two critical vulnerabilities in Bamboo Server and Data Center in its April 21, 2026 security bulletin; the most severe is CVE-2026-21571, an authenticated OS command injection (CVSS 9.4) allowing remote arbitrary command execution on affected systems. Organizations using vulnerable Bamboo versions are urged to apply the provided patches immediately to mitigate potential widespread exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.