logo

Critical RCE Alert: Bamboo Data Center Vulnerable to OS Command Injection

ID: f84e4d37-17dc-5603-85ea-2ebf1b30dcc8

STIX ID: report--f84e4d37-17dc-5603-85ea-2ebf1b30dcc8

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-22

Date Updated: 2026-04-23

Author: Ddos

...
...

Atlassian has issued a high-priority advisory for Bamboo Data Center disclosing a critical OS command-injection RCE (CVE-2026-21571, CVSS 9.4) that enables authenticated attackers to execute arbitrary OS commands and fully compromise CI/CD servers; multiple release branches are affected and Atlassian recommends immediate upgrades to specified fixed minimum versions (e.g., 9.6.25, 10.2.18, 12.1.6) to mitigate severe supply-chain and credential exposure risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.