Jenkins Multiple Vulnerabilities
CSIRTS triage
- What
- Multiple unspecified vulnerabilities in Jenkins.
- Who is affected
- Jenkins deployments and instances across affected versions.
- Urgency
- Severity unknown; requires advisory review to determine risk level.
- Action
- Obtain full Jenkins security advisory to identify vulnerability classes, affected versions, and remediation guidance.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Jenkins
Get an email when a new Jenkins advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.hkcert.org/security-bulletin/jenkins-multiple-vulnerabilities_20260903
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-846450.67% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 50% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-846460.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-846470.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-846480.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-846490.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-846500.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-846510.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-846520.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-846530.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-846540.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-84645 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84646 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84647 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84648 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84649 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84650 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84651 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84652 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84653 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84654 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84655 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84656 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84657 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84677 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Jenkins: Multiple Vulnerabilitiescert-bund
- mediumCVE-2026-84677: Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided values (plugin names…nvd
- mediumCVE-2026-84657: In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check th…nvd
- mediumCVE-2026-84656: A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attack…nvd
- mediumCVE-2026-84655: Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing o…nvd
- mediumCVE-2026-84654: In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenki…nvd
- lowCVE-2026-84653: Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) doe…nvd
- highCVE-2026-84652: In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session whe…nvd
- mediumCVE-2026-84651: In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for upda…nvd
- highCVE-2026-84650: In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded fro…nvd
- highCVE-2026-84649: In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.209…nvd
- highCVE-2026-84648: In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape l…nvd
More from HKCERT Security Bulletins
- unknownGitLab Multiple Vulnerabilities2026-09-14
- unknownPhishing Alert - Beware of Phishing Activities Leading to Unauthorised Credit Card Transactions2026-09-14
- unknownMongoDB Multiple Vulnerabilities2026-09-10
- unknownPalo Alto Products Multiple Vulnerabilities2026-09-10
- unknownGoogle Chrome Multiple Vulnerabilities2026-09-10