CVE-2026-21580Patch

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.0, 7.13.0, 7.17.0, 7.19.0, 8.0.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center and Server. This Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability, with a CVSS Score of 8.6, allows an unauthenticated attacker to execute arbitrary HTML or JavaScript code on a victims browser, perform actions as a higher-privileged user, and to get into the system utilizing loopholes exposed from security best-practices being overlooked. Atlassian recommends that Confluence Data Center and Server customers upgrade to latest version, if you are unable to do so, upgrade your instance to one of the specified supported fixed versions: Confluence Data Center and Server 9.2: Upgrade to a release greater than or equal to 9.2.21 Confluence Data Center and Server 10.2: Upgrade to a release greater than or equal to 10.2.13 See the release notes ([https://confluence.atlassian.com/doc/confluence-release-notes-327.html]). You can download the latest version of Confluence Data Center and Server from the download center ([https://www.atlassian.com/software/confluence/download-archives]). This vulnerability was reported via our Bug Bounty program.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-08-19); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-19: 1Mentions · 2026-08-20: 1Patch / Workaround · 2026-08-19: 1Patch / Workaround · 2026-08-20: 1Technical Details · 2026-08-19: 1Technical Details · 2026-08-20: 108-1908-20
Signal classification1 categories
Patch
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CCB Alert@CCBalert
    Patch

    Warning: Vulnerability in #Atlassian #Confluence Data Center & Server. #CVE-2026-21580 CVSS: 9.3. This flaw enables Stored #XSS and Privilege Escalation #PrivEsc! https://jira.atlassian.com/browse/CONFSERVER-104381 #Patch #Patch #Patch

    Post summary

    The tweet announces the Atlassian Confluence CVE‑2026‑21580 vulnerability with a high CVSS score and indicates a patch is available, but it lacks details on PoC, exploit code, or active exploitation.

    01001346
    7.2K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    A Confluence vulnerability, CVE-2026-21580, is a stored XSS flaw (CVSS 8.6) allowing unauthenticated attacks. A Jira flaw also patched. Update now. #Atlassian #Confluence #CVE202621580 #StoredXSS #Jira #InfoSec https://securityonline.info/confluence-vulnerability-cve-2026-21580/

    Post summary

    A stored XSS flaw (CVE‑2026‑21580) with CVSS 8.6 has been disclosed in Confluence; a patch is available and users are urged to update immediately.

    01000440
    12.8K followersView on X

Explore more