Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Atlassian’s September 15, 2026 Security Bulletin identifies fixes for vulnerabilities in Bamboo, Confluence, Jira Software and Jira Service Management Server/Data Center. Administrators should match their exact deployment and installed version to the bulletin, then confirm the upgrade target against current release notes: the fixed versions below were current on September 15, not necessarily the newest releases today.

What the September 2026 bulletin says

Atlassian’s bulletin covers vulnerabilities fixed in product versions released during the preceding month. It reports 144 high-severity vulnerabilities and 17 critical-severity third-party vulnerabilities. Atlassian also says CVEs in its monthly bulletins are assessed as presenting non-critical risk to customers. A severity rating describes a vulnerability; it does not, by itself, establish the risk to a particular installation or mean that every customer faces an immediate critical incident.

The bulletin is for Server and Data Center products. Atlassian says it patches Cloud vulnerabilities without requiring customer action. The product-version guidance below therefore applies to Server/Data Center deployments, not to a Cloud customer-managed upgrade.

Which versions are affected, and what fixes does Atlassian list?

The table reflects the September 15, 2026 bulletin. “Fixed versions” are the versions Atlassian listed on that date; verify the current target in the relevant release notes before upgrading. Atlassian marked the fixed entries shown here as Data Center only.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Product Affected versions listed Fixed versions listed September 15, 2026
Bamboo 12.1.0–12.1.10; 12.0.0–12.0.2; 11.0.0–11.0.8; 10.2.0–10.2.22; 10.1.0–10.1.1; 10.0.2–10.0.3 12.1.11 (LTS); 10.2.23 (Data Center only)
Confluence 10.2.0–10.2.15; 9.2.0–9.2.23; 8.5.16–8.5.31; 7.19.28–7.19.30, among the listed ranges 10.2.17–10.2.18 (LTS); 9.2.24–9.2.25 (Data Center only)
Jira Software Not stated in the September 15, 2026 bulletin details summarized here; consult the Jira Software entry in Atlassian’s bulletin for the affected ranges. 11.3.11 (LTS); 10.3.25 (Data Center only)
Jira Service Management Not stated in the September 15, 2026 bulletin details summarized here; consult the Jira Service Management entry in Atlassian’s bulletin for the affected ranges. 11.3.11 (LTS); 10.3.25 (Data Center only)

Source for the product ranges and fixed versions: Atlassian, “Security Bulletin – September 15 2026.” The bulletin has separate Jira Software and Jira Service Management entries, so check the correct product row as well as the version. The Confluence ranges above are examples of the older branches included in its table, not an exhaustive reproduction of every listed range.

How to decide whether your installation needs an upgrade

  1. Identify the deployment type. Establish whether the installation is Server, Data Center or Cloud. The bulletin’s version tables concern Server/Data Center products; Cloud vulnerabilities are patched by Atlassian without customer action.
  2. Record the exact product and installed version. Distinguish Bamboo, Confluence, Jira Software and Jira Service Management. For Jira, do not treat one product’s entry as a substitute for the other.
  3. Compare that version with the matching affected range. Check the exact product entry in Atlassian’s September 15 bulletin. A version being absent from the ranges reproduced above does not establish that it is unaffected; the table here is not a substitute for the complete product-specific bulletin.
  4. Confirm a supported current target. The fixed versions in this article reflect Atlassian’s bulletin on September 15, 2026. Check its linked release notes for a newer release before planning remediation. Atlassian advises moving to a latest or LTS version if a feature version is not listed.
  5. Plan and verify the change. Follow your organization’s normal backup, compatibility, testing and change-control procedures. After upgrading, verify the running product version against the selected release and review service health.

Why a high or critical rating is not a complete risk assessment

Atlassian’s count combines high-severity vulnerabilities with critical-severity third-party vulnerabilities in the September bulletin; it does not say that every listed issue is equally exploitable or equally consequential in every environment. The bulletin’s statement that monthly CVEs present non-critical risk to customers is Atlassian’s assessment of those CVEs, not a guarantee that every deployment has no exposure or needs no action.

Prioritize the decision using the facts that apply to your environment: the product and exact version, whether it falls in an affected range, how the service is exposed, and the operational impact of leaving it unpatched. The bulletin alone does not rank an individual organization’s risk or establish exploit activity for its installation.

What if your version is not listed?

Do not assume that an unlisted version is safe. Atlassian notes that some feature versions may be unsupported and recommends moving to a latest or LTS version. Check the complete product-specific bulletin entry and the release notes for the branch you run; if the installed branch has no applicable fixed version, use Atlassian’s current supported upgrade guidance to select a target.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Does this bulletin apply to Atlassian Cloud?

No customer-managed version upgrade is indicated by this Server/Data Center bulletin for Cloud. Atlassian says Cloud vulnerabilities are patched without customer action. The fixed-version table is for administrators managing the listed Server/Data Center products.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.