Jenkins Multiple Vulnerabilities
CSIRTS triage
- What
- Multiple vulnerabilities in Jenkins.
- Who is affected
- Jenkins deployments with unpatched versions.
- Urgency
- Requires review of individual CVE details to assess urgency.
- Action
- Apply Jenkins security updates corresponding to the published CVEs.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Jenkins
Get an email when a new Jenkins advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.hkcert.org/security-bulletin/jenkins-multiple-vulnerabilities_20260806
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-704260.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704270.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704280.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704290.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-704300.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-70426 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-70427 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-70428 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-70429 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-70430 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Jenkins Plugins: Multiple vulnerabilitiescert-bund
- lowCVE-2026-70430: Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that…nvd
- highCVE-2026-70429: Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names an…nvd
- mediumCVE-2026-70428: Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting…nvd
- mediumCVE-2026-70427: Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with …nvd
- criticalCVE-2026-70426: In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkin…nvd
- unknownJenkins Security Advisory 2026-08-05jenkins
More from HKCERT Security Bulletins
- unknownApple macOS Security Restriction Bypass Vulnerability2026-08-07
- unknownGoogle Chrome Multiple Vulnerabilities2026-08-07
- unknownDebian Linux Kernel Multiple Vulnerabilities2026-08-06
- unknownCisco Products Multiple Vulnerabilities2026-08-06
- unknownTP-Link Omada Products Multiple Vulnerabilities2026-08-05