CVE-2026-70443
An attacker can exploit multiple vulnerabilities in Jenkins to execute arbitrary code, escalate privileges, bypass security measures, disclose confidential information, manipulate data as well as perform cross-site scripting (XSS) or server-side request forgery (SSRF) attacks.
CSIRTS triage
- What
- Multiple vulnerabilities in Jenkins plugins enable remote code execution, privilege escalation, authentication bypass, information disclosure, and SSRF attacks.
- Who is affected
- All Jenkins installations using affected plugins are at risk.
- Urgency
- High severity with multiple attack vectors including unauthenticated RCE; immediate patching is critical.
- Action
- Update all Jenkins plugins to patched versions; identify and list which specific plugins are affected and their version numbers from Jenkins security advisories.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-70443
Get an email if CVE-2026-70443 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
Advisory coverage (3)
- high[NEW] [high] Jenkins Plugins: Multiple vulnerabilitiescert-bund · 2026-08-06
- mediumCVE-2026-70443: Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate con…nvd · 2026-08-05
- unknownJenkins Security Advisory 2026-08-05jenkins · 2026-08-05
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-70443)