Security Bulletin - September 15 2026
CVE-2019-13990 - XXE (XML External Entity Injection) Vulnerability In Jira Service Management Data Center and Jira Service Management Server
CVE-2022-1471 - SnakeYAML library RCE Vulnerability impacts Multiple Products
CVE-2023-22522 - RCE Vulnerability In Confluence Data Center and Confluence Server
CVE-2023-22523 - RCE Vulnerability in Assets Discovery
CVE-2023-22524 - RCE Vulnerability in Atlassian Companion App for MacOS
CVE-2023-22527 - RCE (Remote Code Execution) Vulnerability In Confluence Data Center and Confluence Server
CVE-2023-22518 - Improper Authorization Vulnerability In Confluence Data Center and Server
CVE-2023-46604 - Apache ActiveMQ RCE Vulnerability impacts Bamboo Data Center and Server
Multiple Products Security Advisory - Git Buffer Overflow - CVE-2022-41903, CVE-2022-23521
Security Bulletin - July 18 2023
Security Bulletin - August 15 2023
Security Bulletin - September 19 2023
Security Bulletin - October 17 2023
Security Bulletin - November 21 2023
Security Bulletin - December 12 2023
Security Bulletin - January 16 2024
Security Bulletin - February 20 2024
Security Bulletin - March 19 2024
Security Bulletin - April 16 2024
Security Bulletin - May 21 2024
Security Bulletin - June 18 2024
Security Bulletin - July 16 2024
Security Bulletin - August 20 2024
Security Bulletin - September 17 2024
Security Bulletin - October 15 2024
Security Bulletin - November 19 2024
Security Bulletin - December 10 2024
Security Bulletin - January 21 2025
Security Bulletin - February 18 2025
Security Bulletin - March 18 2025
Security Bulletin - April 15 2025
Security Bulletin - May 20 2025
Security Bulletin - June 17 2025
Security Bulletin - July 15 2025
Security Bulletin - August 19 2025
Security Bulletin - September 16 2025
Security Bulletin - October 21 2025
Security Bulletin - November 18 2025
Security Bulletin - December 11 2025
Security Bulletin - January 20 2026
Security Bulletin - February 17 2026
Security Bulletin - March 17 2026
Security Bulletin - April 21 2026
Security Bulletin - May 19 2026
Security Bulletin - June 16 2026
Security Bulletin - July 21 2026
Security Bulletin - August 18 2026
Security Bulletin - September 15 2026
The Atlassian Community is here for you.
The vulnerabilities reported in this Security Bulletin include 144 high-severity vulnerabilities and 17 critical-severity third-party vulnerabilities, which have been fixed in new versions of our products released in the last month.
CVEs reported in monthly Security Bulletins have been assessed as presenting a non-critical risk to Atlassian customers. Atlassian issues Critical Security Advisories for vulnerabilities that pose an immediate critical risk based on how our products actually use the affected components outside of our monthly Security Bulletin schedule as necessary.
Vulnerabilities are discovered through our Bug Bounty program, pen-testing processes, and third-party library scans.
To fix all the vulnerabilities impacting your product(s), Atlassian recommends patching your instances to the latest version or one of the Fixed Versions for each product below. The listed Fixed Versions for each product are current as of September 15, 2026 (date of publication); visit the linked product Release Notes for the most up-to-date versions.
To for CVEs or check your product versions for disclosed vulnerabilities, check the Vulnerability Disclosure Portal.
12.1.0 to 12.1.10 (LTS)
10.2.0 to 10.2.22 (LTS)
12.1.11 (LTS) recommended Data Center Only
10.2.23 (LTS) Data Center Only
This is a vulnerability in a non-Atlassian Bamboo dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.
10.2.0 to 10.2.5 (LTS)
9.4.0 to 9.4.23 (LTS)
10.4.2 to 10.4.3 Data Center Only
10.2.6 to 10.2.7 (LTS) recommended Data Center Only
9.4.24 (LTS) Data Center Only
10.2.0 to 10.2.15 (LTS)
9.2.0 to 9.2.23 (LTS)
8.5.16 to 8.5.31 (LTS)
7.19.28 to 7.19.30 (LTS)
10.2.17 to 10.2.18 (LTS) recommended Data Center Only
9.2.24 to 9.2.25 (LTS) Data Center Only
This is a vulnerability in a non-Atlassian Confluence dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.
This is a vulnerability in a non-Atlassian Confluence dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.
This is a vulnerability in a non-Atlassian Confluence dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.
This is a vulnerability in a non-Atlassian Confluence dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.
This is a vulnerability in a non-Atlassian Confluence dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.
This is a vulnerability in a non-Atlassian Confluence dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.
7.2.3 recommended Data Center Only
This is a vulnerability in a non-Atlassian Fisheye/Crucible dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.
This is a vulnerability in a non-Atlassian Fisheye/Crucible dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.
11.3.0 to 11.3.10 (LTS)
10.3.0 to 10.3.24 (LTS)
9.12.14 to 9.12.38 (LTS)
11.3.11 (LTS) recommended Data Center Only
10.3.25 (LTS) Data Center Only
This is a vulnerability in a non-Atlassian Jira Software dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.
This is a vulnerability in a non-Atlassian Jira Software dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.
This is a vulnerability in a non-Atlassian Jira Software dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.
This is a vulnerability in a non-Atlassian Jira Software dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.
11.3.0 to 11.3.10 (LTS)
10.3.0 to 10.3.24 (LTS)
11.3.11 (LTS) recommended Data Center Only
10.3.25 (LTS) Data Center Only
This is a vulnerability in a non-Atlassian Jira Service Management dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.
This is a vulnerability in a non-Atlassian Jira Service Management dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.
This is a vulnerability in a non-Atlassian Jira Service Management dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.
This is a vulnerability in a non-Atlassian Jira Service Management dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.
Why is my Feature Version not listed in a Fixed Version? You may be using an unsupported version and need to patch to the latest version or Long-Term Support (LTS) version.
Why is my Feature Version not listed in a Fixed Version? You may be using an unsupported version and need to patch to the latest version or Long-Term Support (LTS) version.
What are the most up-to-date Data Center product versions? You can always check the software download portal or visit the product-specific download pages. Jira Software Data Center Jira Service Management Confluence Data Center Bitbucket Data Center Bamboo Data Center Crowd Data Center
Jira Service Management
Jira Service Management
I am using an LTS, why is it not listed in the Fixed Versions? Your LTS version may not have been updated yet or a backported fix may not have been feasible. Please see our Security Bug Fix Policy for more information. We recommend upgrading your products to the latest versions. For the latest fixed versions, visit the release notes linked in the vulnerability table.
I am using an LTS, why is it not listed in the Fixed Versions? Your LTS version may not have been updated yet or a backported fix may not have been feasible. Please see our Security Bug Fix Policy for more information. We recommend upgrading your products to the latest versions. For the latest fixed versions, visit the release notes linked in the vulnerability table.
To for CVEs or check your products versions for disclosed vulnerabilities, check the Vulnerability Disclosure Portal.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
