PatchSiren cyber security CVE debrief
CVE-2026-21575 Atlassian CVE debrief
CVE-2026-21575 is a High severity RCE (Remote Code Execution) vulnerability introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows. The vulnerability has a CVSS Score of 7.1 and allows an authenticated attacker to execute arbitrary code, impacting confidentiality, integrity, and availability. User interaction is required. This vulnerability affects users of Sourcetree for Mac and Sourcetree for Windows, particularly those using version 3.4.11. An immediate review of current deployments and an upgrade plan should be prioritized.
- Vendor
- Atlassian
- Product
- Sourcetree for Mac
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-22
Who should care
Users of Sourcetree for Mac and Sourcetree for Windows, especially those using version 3.4.11, should upgrade to a fixed version to prevent potential RCE attacks. This includes operators, platform administrators, vulnerability management teams, and security teams responsible for maintaining and securing their software development environments.
Technical summary
The vulnerability, with a CVSS Score of 7.1, allows an authenticated attacker to execute arbitrary code which has high impact to confidentiality, high impact to integrity, high impact to availability, and requires user interaction. It was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows. The vulnerability can be mitigated by upgrading to a fixed version, specifically for Sourcetree for Mac and Sourcetree for Windows 3.4: Upgrade to a release greater than or equal to 3.4.13.
Defensive priority
High priority should be given to upgrading Sourcetree for Mac and Sourcetree for Windows to a fixed version, as the vulnerability allows for RCE and requires user interaction.
Recommended defensive actions
- Upgrade Sourcetree for Mac and Sourcetree for Windows to the latest version.
- If immediate upgrade is not possible, upgrade to one of the specified supported fixed versions: Sourcetree for Mac and Sourcetree for Windows 3.4: Upgrade to a release greater than or equal to 3.4.13.
- Review and apply the release notes and download the latest version from the official download center.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The vulnerability was reported via the Bug Bounty program. Limited details are available about the specific attack vector or exploitability. Further review of system logs and network traffic may be necessary to detect potential exploitation attempts. Additional verification steps should include checking for any suspicious activity related to user interactions with the affected Sourcetree versions.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T18:16:57.170Z and has not been modified since then.