Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Atlassian’s September 15, 2026 Security Bulletin lists affected and fixed versions for Bamboo, Confluence, Crowd, and Jira Data Center and Server. Administrators should identify the exact product, deployment type, and installed release branch, then compare that version with Atlassian’s affected-version table. The fixed-version guidance below reflects the bulletin as of September 15, 2026; check Atlassian’s current advisory index and linked product release notes before updating.

What the September bulletin covers

Atlassian says the bulletin covers 144 high-severity and 17 critical-severity third-party vulnerabilities fixed in product releases from the preceding month. Those are bulletin-wide counts, not vulnerability totals for any one product.

The bulletin addresses Bamboo, Confluence, Crowd, and Jira Data Center and Server. These version ranges do not establish whether a Cloud product is affected; Cloud administrators should consult the relevant Cloud advisories and product information instead.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Atlassian says it assesses monthly bulletin CVEs as non-critical risk to its customers. It issues separate Critical Security Advisories when a vulnerability presents immediate critical risk, based on how the product uses the affected component. Some bulletin entries concern third-party dependencies, and an upstream component’s severity may not match Atlassian’s assessment of risk in its product. The reported severity of a dependency should therefore not be read as Atlassian’s customer-risk assessment.

Which versions are affected, and what versions are fixed?

This table summarizes representative branches from Atlassian’s September 15 bulletin, not every branch or row in its affected-version table. A version range marked “among other branches” is not exhaustive. “LTS” means Atlassian marks that branch as a Long Term Support branch in the bulletin.

Product and deployment scope Representative affected versions Listed fixed versions
Bamboo Data Center and Server 12.1.0–12.1.10 (LTS); 12.0.0–12.0.2; 11.0.0–11.0.8; 10.2.0–10.2.22 (LTS); 10.1.0–10.1.1; 10.0.2–10.0.3 12.1.11 (LTS; recommended, Data Center only); 10.2.23 (LTS; Data Center only)
Confluence Data Center and Server 10.2.0–10.2.15 (LTS); 10.1.0–10.1.2; 10.0.2–10.0.3; 9.5.1–9.5.4; 9.2.0–9.2.23 (LTS); 8.5.16–8.5.31 (LTS); 7.19.28–7.19.30 (LTS), among other listed branches 10.2.17–10.2.18 (LTS; recommended, Data Center only); 9.2.24–9.2.25 (LTS; Data Center only)
Crowd Data Center and Server 7.2.0–7.2.2; 7.1.0–7.1.5; 7.0.0–7.0.2; 6.3.0–6.3.6; 6.2.0–6.2.6; 6.1.0–6.1.7 7.2.3 (recommended, Data Center only)
Jira Data Center and Server 11.3.0–11.3.10 (LTS); 11.2.0–11.2.1; 11.1.0–11.1.1; 11.0.0–11.0.1; 10.7.1–10.7.4; 10.3.0–10.3.24 (LTS); 9.12.14–9.12.38 (LTS), among other listed branches 11.3.11 (LTS; recommended, Data Center only); 10.3.25 (LTS; Data Center only)

Fixed-version options are branch-specific, not interchangeable across products or installations. In particular, the bulletin labels some fixed releases “Data Center only.” Do not assume those releases are suitable for a Server installation; check the applicable product release notes and current guidance for that deployment type. The bulletin’s fixed-version recommendations were current on September 15, 2026, and may have changed since.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to check whether an installation is affected

  1. Identify the installation. Record the product (Bamboo, Confluence, Crowd, or Jira), whether it is Data Center or Server, and its exact installed version. Do not use a version from a different product or deployment type as a comparison.
  2. Find the matching product section. In Atlassian’s September 15, 2026 Security Bulletin, locate that product’s affected-version table and match the installed version to the exact branch and range. The representative ranges above are not a substitute for the full table.
  3. Choose a compatible remediation. Atlassian’s instruction is: “To fix all the vulnerabilities impacting your product(s), Atlassian recommends patching your instances to the latest version or one of the Fixed Versions for each product below.” Check that the selected fixed release applies to the installation’s product, deployment type, and branch.
  4. Verify current release guidance before patching. Use the bulletin’s linked product release notes for the latest versions and update details. Atlassian also directs administrators to its Vulnerability Disclosure Portal to search CVEs or check product versions.

The bulletin says vulnerabilities are discovered through Atlassian’s Bug Bounty program, penetration testing, and third-party library scans. Its advisory index lists September 15, 2026 as the latest monthly bulletin available as of October 4, 2026; that date does not establish what advisories were published later.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.