Atlassian disclosed a critical OS command injection vulnerability, CVE-2026-21571, in Bamboo Data Center and Server that can let an authenticated attacker execute arbitrary operating system commands and potentially fully compromise vulnerable CI/CD servers. The flaw carries a CVSS 4.0 score of 9.4, requires no user interaction, and affects Bamboo Data Center versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0. Atlassian warned that exploitation could impact confidentiality, integrity, availability, and downstream system security, with added risk to build pipelines, stored credentials, and software supply chains.
Atlassian also reported a separate high-severity denial-of-service issue, CVE-2026-33871, in the bundled io.netty:netty-codec-http2 dependency that could be abused for HTTP/2-based service disruption. The company urged organizations to patch immediately by upgrading to fixed releases, including 9.6.25 or later, 10.2.18 or later, and 12.1.6 or later, with 10.2.18 LTS and 12.1.6 LTS highlighted as recommended targets. Until upgrades are completed, administrators were advised to review deployed Bamboo versions and restrict network access to Bamboo administrative interfaces as a temporary mitigation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Atlassian also disclosed CVE-2026-33871, a high-severity denial-of-service vulnerability affecting Bamboo through the bundled io.netty:netty-codec-http2 dependency. The issue carries a CVSS score of 8.7 and could enable HTTP/2-based service disruption on vulnerable Bamboo instances.
Atlassian published a broader April 21, 2026 security bulletin covering multiple vulnerabilities across Bamboo, Bitbucket, Confluence, Jira Software, and Jira Service Management Data Center and Server products. The advisory included fixed release guidance for affected products, including Bitbucket 10.2.2/9.4.19, Confluence 10.2.10/9.2.19, and Jira/JSM 11.3.4/10.3.19, alongside Bamboo updates already separately disclosed.
Atlassian advised customers to upgrade to patched releases, including 9.6.25 or later, 10.2.18 or later, and 12.1.6 or later, and urged immediate patching. It also recommended reviewing deployed versions and applying network-level restrictions to Bamboo administrative interfaces as a temporary mitigation.
Atlassian disclosed CVE-2026-21571, a critical OS command injection vulnerability in Bamboo Data Center that can allow authenticated remote code execution. The flaw affects Bamboo Data Center versions 9.6.0, 10.0.0, 10.1.0, 10.2.0, 11.0.0, 11.1.0, 12.0.0, and 12.1.0 and was assigned a CVSS 4.0 score of 9.4.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceconfluence.atlassian.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.