
What is CVE-2026-21580?
CVE-2026-21580 is a stored cross-site scripting vulnerability in Atlassian Confluence Data Center and Server, which the vendor advisory groups together with a privilege escalation component and a security misconfiguration weakness. An attacker persists crafted HTML or JavaScript on a vulnerable instance, and that payload executes later in the browser of whichever user views the affected content.
The vulnerability carries a CVSS 4.0 base score of 8.6. Atlassian labels the issue Critical under its own advisory taxonomy, while the numeric score falls in the High band under standard CVSS severity ranges. Teams that triage against a score-driven patching policy should be aware that the vendor label and the score point to different tiers.
Exploitation does not require authentication. An attacker with network access to the Confluence instance can plant the payload without valid credentials, which removes the usual assumption that a wiki behind a login page is only reachable by known users. The privilege escalation follows from who reads the page rather than who writes it. When the viewer holds administrative or space-administrator rights, the injected script runs with that session’s authority and can perform actions the attacker could not perform directly.
The flaw was reported through Atlassian’s bug bounty program. Atlassian reports no confirmed in-the-wild exploitation at the time of writing.
What assets are affected by CVE-2026-21580?
The affected software is Confluence Data Center and Server, self-hosted. Atlassian lists the vulnerability as introduced across a long series of releases spanning 7.1.1 through 10.2.0, which covers most of the currently deployed on-premises estate. Confluence Cloud is not in scope.
In practice an affected asset is a self-managed wiki, knowledge base, or service desk front end, typically running behind a reverse proxy on 443 or on a non-standard TLS port such as 8443. Deployment patterns vary widely: some instances run on dedicated hardware in a corporate data center, others on cloud virtual machines that were lifted and shifted without changing the exposure model. Hostnames follow predictable conventions, which makes these assets easy for an attacker to enumerate and easy for a defender to lose track of.
These systems tend to be internet-facing for a reason. Confluence is often the shared documentation layer between an organization and its contractors, partners, or distributed engineering teams, so public reachability is a deliberate choice rather than a misconfiguration. The overlooked category is different. Staging wikis, test service desks, and instances inherited through acquisition frequently outlive the projects that created them, stay on an old release line, and fall outside the patch cycle applied to the production instance.
What does our data show about exposure patterns?

Exposure in this set is led by Consumer Discretionary at 27.6% of observed assets, with Industrials and Information Technology each contributing 15.5%. These assets were predominantly identified by service fingerprint rather than by confirmed version detection, so the set represents systems observed running Confluence Data Center or Server and potentially affected, not systems confirmed to be running a vulnerable build.
The Consumer Discretionary concentration fits the operating model of retail, hospitality, and consumer brand organizations. They run large supplier and franchise networks, they document processes for staff who are not on the corporate network, and they acquire and divest brands at a pace that leaves documentation infrastructure attached to entities nobody currently owns. A wiki set up for a seasonal campaign or a brand integration is exactly the kind of asset that keeps answering on the internet long after the team that built it moved on. Industrials shows a similar shape for a different reason: distributed sites, long-lived engineering documentation, and partner access requirements that make external reachability the path of least resistance.
The largest share in this set is the Others bucket at 41.4%, and a substantial part of that is exposure at organizations whose industry could not be classified at all. That is the more useful signal. Confluence exposure is not concentrated in one vertical, it tracks wherever teams needed to share documentation across an organizational boundary. The common driver is not a sector-specific practice but a lifecycle gap: instances are stood up quickly to solve a collaboration problem, they inherit the availability requirements of a production service, and they rarely inherit the patch discipline of one.
Are fixes available?
Patches are available. Atlassian has published fixed releases and recommends upgrading to the latest version of Confluence Data Center and Server. For organizations that cannot move to the latest release, the vendor names supported fixed versions on the maintained lines: 9.2.21 or later on the 9.2 line, and 10.2.13 or later on the 10.2 line.
The caveat is coverage across older lines. The affected range reaches back to 7.1.1, and organizations running release lines that Atlassian no longer maintains will not find a targeted fix for their current version. For those instances the remediation is a version upgrade rather than a patch, which is a materially larger piece of work and one that tends to get deferred.
Defenders should confirm fixed-version guidance directly against Atlassian’s advisory for the specific release line they run rather than assuming a patch exists for their current build. Third-party trackers summarizing this CVE have not been consistent about the score or the severity label, which is a reasonable prompt to work from the vendor advisory rather than an aggregator.
Are there any other recommended actions to take?
Alongside patching, defenders should:
- Inventory all self-hosted Confluence instances, including staging and inherited deployments
- Restrict Confluence access to trusted networks or an authenticated VPN
- Audit user and group permissions for unexpected administrator or space-admin grants
- Monitor Confluence logs for anomalous page edits from unauthenticated sources
- Review Content Security Policy headers at the Confluence reverse proxy
How can CyCognito help your organization?
CyCognito published an Emerging Threat Advisory for CVE-2026-21580 in the CyCognito platform and is actively researching enhanced detection capabilities for this vulnerability.
To learn how CyCognito can help your organization reduce external exposure and manage emerging threats more effectively, contact us to request a demo.