Jenkins Multiple Vulnerabilities
CSIRTS triage
- What
- Multiple unspecified vulnerabilities in Jenkins.
- Who is affected
- Jenkins deployments and instances across affected versions.
- Urgency
- Severity unknown; requires advisory review to determine risk level.
- Action
- Obtain full Jenkins security advisory to identify vulnerability classes, affected versions, and remediation guidance.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Jenkins
Get an email when a new Jenkins advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.hkcert.org/security-bulletin/jenkins-multiple-vulnerabilities_20260903
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-84645 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84646 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84647 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84648 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84649 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84650 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84651 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84652 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84653 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84654 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84655 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84656 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84657 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-84677 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Jenkins: Multiple Vulnerabilitiescert-bund
- mediumCVE-2026-84677: Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided values (plugin names…nvd
- mediumCVE-2026-84657: In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check th…nvd
- mediumCVE-2026-84656: A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attack…nvd
- mediumCVE-2026-84655: Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing o…nvd
- mediumCVE-2026-84654: In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenki…nvd
- unknownCVE-2026-84653: Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) doe…nvd
- unknownCVE-2026-84652: In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session whe…nvd
- mediumCVE-2026-84651: In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for upda…nvd
- highCVE-2026-84650: In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded fro…nvd
- highCVE-2026-84649: In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.209…nvd
- highCVE-2026-84648: In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape l…nvd
More from HKCERT Security Bulletins
- unknownCisco Products Multiple Vulnerabilities2026-09-03
- unknownGitHub Enterprise Server Multiple Vulnerabilities2026-09-03
- unknownMozilla Products Multiple Vulnerabilities2026-09-02
- unknownGoogle Chrome Multiple Vulnerabilities2026-09-02
- unknownF5 Products Multiple Vulnerabilities2026-09-02