Skip to content

Security Bulletin - September 15 2026

Confluence.Atlassian September 16, 2026

CVE-2019-13990 - XXE (XML External Entity Injection) Vulnerability In Jira Service Management Data Center and Jira Service Management Server

CVE-2022-1471 - SnakeYAML library RCE Vulnerability impacts Multiple Products

CVE-2023-22522 - RCE Vulnerability In Confluence Data Center and Confluence Server

CVE-2023-22523 - RCE Vulnerability in Assets Discovery

CVE-2023-22524 - RCE Vulnerability in Atlassian Companion App for MacOS

CVE-2023-22527 - RCE (Remote Code Execution) Vulnerability In Confluence Data Center and Confluence Server

CVE-2023-22518 - Improper Authorization Vulnerability In Confluence Data Center and Server

CVE-2023-46604 - Apache ActiveMQ RCE Vulnerability impacts Bamboo Data Center and Server

Multiple Products Security Advisory - Git Buffer Overflow - CVE-2022-41903, CVE-2022-23521

Security Bulletin - July 18 2023

Security Bulletin - August 15 2023

Security Bulletin - September 19 2023

Security Bulletin - October 17 2023

Security Bulletin - November 21 2023

Security Bulletin - December 12 2023

Security Bulletin - January 16 2024

Security Bulletin - February 20 2024

Security Bulletin - March 19 2024

Security Bulletin - April 16 2024

Security Bulletin - May 21 2024

Security Bulletin - June 18 2024

Security Bulletin - July 16 2024

Security Bulletin - August 20 2024

Security Bulletin - September 17 2024

Security Bulletin - October 15 2024

Security Bulletin - November 19 2024

Security Bulletin - December 10 2024

Security Bulletin - January 21 2025

Security Bulletin - February 18 2025

Security Bulletin - March 18 2025

Security Bulletin - April 15 2025

Security Bulletin - May 20 2025

Security Bulletin - June 17 2025

Security Bulletin - July 15 2025

Security Bulletin - August 19 2025

Security Bulletin - September 16 2025

Security Bulletin - October 21 2025

Security Bulletin - November 18 2025

Security Bulletin - December 11 2025

Security Bulletin - January 20 2026

Security Bulletin - February 17 2026

Security Bulletin - March 17 2026

Security Bulletin - April 21 2026

Security Bulletin - May 19 2026

Security Bulletin - June 16 2026

Security Bulletin - July 21 2026

Security Bulletin - August 18 2026

Security Bulletin - September 15 2026

The Atlassian Community is here for you.

The vulnerabilities reported in this Security Bulletin include 144 high-severity vulnerabilities and 17 critical-severity third-party vulnerabilities, which have been fixed in new versions of our products released in the last month.

CVEs reported in monthly Security Bulletins have been assessed as presenting a non-critical risk to Atlassian customers. Atlassian issues Critical Security Advisories for vulnerabilities that pose an immediate critical risk based on how our products actually use the affected components outside of our monthly Security Bulletin schedule as necessary.

Vulnerabilities are discovered through our Bug Bounty program, pen-testing processes, and third-party library scans.

To fix all the vulnerabilities impacting your product(s), Atlassian recommends patching your instances to the latest version or one of the Fixed Versions for each product below. The listed Fixed Versions for each product are current as of September 15, 2026 (date of publication); visit the linked product Release Notes for the most up-to-date versions.

To for CVEs or check your product versions for disclosed vulnerabilities, check the Vulnerability Disclosure Portal.

12.1.0 to 12.1.10 (LTS)

10.2.0 to 10.2.22 (LTS)

12.1.11 (LTS) recommended Data Center Only

10.2.23 (LTS) Data Center Only

This is a vulnerability in a non-Atlassian Bamboo dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

10.2.0 to 10.2.5 (LTS)

9.4.0 to 9.4.23 (LTS)

10.4.2 to 10.4.3 Data Center Only

10.2.6 to 10.2.7 (LTS) recommended Data Center Only

9.4.24 (LTS) Data Center Only

10.2.0 to 10.2.15 (LTS)

9.2.0 to 9.2.23 (LTS)

8.5.16 to 8.5.31 (LTS)

7.19.28 to 7.19.30 (LTS)

10.2.17 to 10.2.18 (LTS) recommended Data Center Only

9.2.24 to 9.2.25 (LTS) Data Center Only

This is a vulnerability in a non-Atlassian Confluence dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

This is a vulnerability in a non-Atlassian Confluence dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

This is a vulnerability in a non-Atlassian Confluence dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

This is a vulnerability in a non-Atlassian Confluence dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

This is a vulnerability in a non-Atlassian Confluence dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

This is a vulnerability in a non-Atlassian Confluence dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

7.2.3 recommended Data Center Only

This is a vulnerability in a non-Atlassian Fisheye/Crucible dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

This is a vulnerability in a non-Atlassian Fisheye/Crucible dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

11.3.0 to 11.3.10 (LTS)

10.3.0 to 10.3.24 (LTS)

9.12.14 to 9.12.38 (LTS)

11.3.11 (LTS) recommended Data Center Only

10.3.25 (LTS) Data Center Only

This is a vulnerability in a non-Atlassian Jira Software dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

This is a vulnerability in a non-Atlassian Jira Software dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

This is a vulnerability in a non-Atlassian Jira Software dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

This is a vulnerability in a non-Atlassian Jira Software dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

11.3.0 to 11.3.10 (LTS)

10.3.0 to 10.3.24 (LTS)

11.3.11 (LTS) recommended Data Center Only

10.3.25 (LTS) Data Center Only

This is a vulnerability in a non-Atlassian Jira Service Management dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

This is a vulnerability in a non-Atlassian Jira Service Management dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

This is a vulnerability in a non-Atlassian Jira Service Management dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

This is a vulnerability in a non-Atlassian Jira Service Management dependency. Atlassian's application of this dependency presents a lower, non-critical assessed risk.

Why is my Feature Version not listed in a Fixed Version? You may be using an unsupported version and need to patch to the latest version or Long-Term Support (LTS) version.

Why is my Feature Version not listed in a Fixed Version? You may be using an unsupported version and need to patch to the latest version or Long-Term Support (LTS) version.

What are the most up-to-date Data Center product versions? You can always check the software download portal or visit the product-specific download pages. Jira Software Data Center Jira Service Management Confluence Data Center Bitbucket Data Center Bamboo Data Center Crowd Data Center

Jira Software Data Center

Jira Software Data Center

Jira Service Management

Jira Service Management

Confluence Data Center

Confluence Data Center

Bitbucket Data Center

Bitbucket Data Center

I am using an LTS, why is it not listed in the Fixed Versions? Your LTS version may not have been updated yet or a backported fix may not have been feasible. Please see our Security Bug Fix Policy for more information. We recommend upgrading your products to the latest versions. For the latest fixed versions, visit the release notes linked in the vulnerability table.

I am using an LTS, why is it not listed in the Fixed Versions? Your LTS version may not have been updated yet or a backported fix may not have been feasible. Please see our Security Bug Fix Policy for more information. We recommend upgrading your products to the latest versions. For the latest fixed versions, visit the release notes linked in the vulnerability table.

To for CVEs or check your products versions for disclosed vulnerabilities, check the Vulnerability Disclosure Portal.