What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Atlassian’s September 15, 2026 Security Bulletin reports fixes for 144 high-severity vulnerabilities and 17 critical-severity third-party vulnerabilities in new releases issued during the preceding month. One example is a remote code execution (RCE) issue in the io.netty dependency used by Bamboo Data Center, CVE-2026-75595, scored CVSS 9.1 Critical. Atlassian nevertheless assessed the risk of this dependency issue in its products as lower and non-critical; the bulletin is a broad update for self-managed products, not a notice that every listed issue presents an emergency.

What Atlassian’s September 2026 bulletin covers

The bulletin covers Server and Data Center products, including Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, Jira Software, and Jira Service Management. Its figures—144 high-severity vulnerabilities and 17 critical-severity third-party vulnerabilities—refer to issues fixed in product versions released in the preceding month, as reported by Atlassian on September 15, 2026. The bulletin also says its listed CVEs were assessed as presenting non-critical risk to Atlassian customers.

Atlassian distinguishes these monthly bulletin entries from Critical Security Advisories. It says the latter are used for vulnerabilities that pose an immediate critical risk, based on how the affected component is used in an Atlassian product. The company says vulnerabilities are identified through its Bug Bounty program, penetration testing, and scans of third-party libraries. See the September 2026 Security Bulletin for the product-specific entries.

Which Atlassian versions are affected?

There is no single affected version range for the whole bulletin. Each product and vulnerability has its own affected releases and fixed versions, and some products have separate release branches. Match your deployment type, product, and exact installed version against the corresponding table in Atlassian’s bulletin; do not apply one product’s version range to another.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

Bamboo Data Center example: CVE-2026-75595

For the cited RCE in the io.netty dependency, Atlassian lists Bamboo Data Center versions 12.1.0 through 12.1.10 and 10.2.0 through 10.2.22 as affected. The bulletin lists 12.1.11 (LTS) as the recommended fixed release and 10.2.23 (LTS) as another fixed Data Center version. These ranges and recommendations are the values published on September 15, 2026; they should not be assumed to remain the latest release guidance.

The CVSS 9.1 Critical score describes the vulnerability in the dependency. Atlassian says its use of this non-Atlassian component presents a lower, non-critical assessed risk in its product. That distinction matters: a component’s CVSS score alone does not establish the risk in a particular product or deployment.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

What version fixes the Atlassian RCE?

For CVE-2026-75595 in the listed Bamboo Data Center branches, the bulletin gives 12.1.11 (LTS) and 10.2.23 (LTS) as fixed versions. This answer applies only to that Bamboo Data Center entry, not to other products or vulnerabilities in the bulletin. Atlassian recommends updating affected instances to the latest version or a fixed version listed for the relevant product, and says the linked release notes contain the most up-to-date version information.

How to check and patch a self-managed installation

  1. Identify your deployment. Confirm whether the product is Atlassian Server or Data Center, and record the product name and installed version.
  2. Find the matching bulletin table. Open Atlassian’s Security Bulletin and locate the entry for that product and vulnerability. Compare the installed version with that entry’s affected range and fixed release; do not infer exposure from a different product’s table.
  3. Choose the applicable update. Update to the latest appropriate version or a listed fixed version for the product and release branch. Check the linked release notes before patching, because the bulletin’s version snapshot is dated September 15, 2026.
  4. Verify the installed release. After the update, confirm that the instance is running the intended fixed release and consult the product’s release guidance if your branch or upgrade path is unclear.

Does the September 2026 Atlassian security bulletin affect Confluence Cloud?

No customer-installed patch is called for by this Server and Data Center bulletin for Cloud users. Atlassian Support says the Security Bulletin is for Server and Data Center products and that it can patch Cloud vulnerabilities seamlessly without customer action. Cloud customers should use Atlassian’s Cloud security information rather than applying self-managed product version ranges. See Atlassian Support’s explanation of Security Bulletins.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

Does a critical CVSS score mean Atlassian customers face critical risk?

Not necessarily. A CVSS score characterizes a vulnerability, but the risk to customers also depends on how the product incorporates and uses the affected component. Atlassian says the CVEs in its September monthly bulletin were assessed as non-critical risk to its customers; for the cited Bamboo io.netty issue, it specifically describes its assessed risk as lower and non-critical despite the dependency’s CVSS 9.1 Critical score. A Critical score is not, by itself, proof of an Atlassian Critical Security Advisory or a direction to treat every affected instance as an emergency.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Are these Atlassian vulnerabilities being exploited?

The September 15 bulletin does not establish whether the cited vulnerabilities are being actively exploited. It reports vulnerabilities and fixes, but does not make an exploitation-status claim in the information covered here. Do not treat the CVSS score or the existence of a patch as evidence of active exploitation.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display

Where to confirm the latest release guidance

Atlassian’s security index lists the September 2026 bulletin and says monthly bulletins are released on the third Tuesday of each month. Since the fixed versions above are a dated snapshot, check the relevant product release notes and current bulletin before planning an update. The bulletin’s scope and recommendations are available in Atlassian’s security advisory index.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.