Skip to content

Jenkins vulnerabilities

3 CVEs tracked

During the reporting period, the Jenkins CI/CD server is highlighted for several critical vulnerabilities. The main theme is remote code execution (RCE) and arbitrary file write flaws on the Jenkins controller, exploitable via compromised agent processes. Specifically, attackers controlling agents can achieve RCE through a JEP-200 filter bypass in deserialization (CVE-2026-70426) and write arbitrary files via unsafe symbolic link handling in archive extraction (CVE-2026-70427). Defenders must prioritize upgrading Jenkins to the latest version, restricting agent connections, and reviewing file parameter permissions to mitigate the path traversal risk detailed in CVE-2026-70428.

This vendor's CVEs3

This hub is built from skopnix's own reporting on Jenkins: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.