Jenkins Security Advisory 2026-06-10
Affects Jenkins Core
CSIRTS triage
- What
- This advisory addresses multiple vulnerabilities in Jenkins Core.
- Who is affected
- Deployments of Jenkins Core are affected.
- Urgency
- Remediation is necessary, but the severity is currently unknown.
- Action
- Update to the latest version of Jenkins Core.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Jenkins Core
Get an email when a new Jenkins Core advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.jenkins.io/security/advisory/2026-06-10/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Elevated exploitation riskCVE-2026-5343519.0% 30-day exploitation probability — well above the norm. Schedule remediation this cycle. Riskier than 97% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-534360.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-534370.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-534380.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-534390.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-534400.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-534410.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-534420.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-53435 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-53436 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-53437 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-53438 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-53439 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-53440 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-53441 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-53442 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- mediumGHSA-mw82-xcg6-gx79: Jenkins: Missing permission check allows unauthorized cancellation of queue itemsghsa
- mediumGHSA-3rqh-hch3-jhpc: Jenkins Open Redirect via Relative Path Segments in Post-Login Redirect URLghsa
- mediumGHSA-463r-5m89-4xfr: Jenkins Open Redirect Through Newline/Tab Characters in Redirect URLghsa
- highGHSA-g2xq-2v27-4rh3: Jenkins arbitrary type deserialization from attacker-controlled config.xml allows remote …ghsa
- mediumGHSA-g28p-6mcc-v4rv: Jenkins exposes other users' timezone and view names to users with Overall/Read permissio…ghsa
- mediumGHSA-m6wv-wh8g-64xc: Jenkins does not encrypt secrets from POST config.xml submissions before storing them in …ghsa
- mediumGHSA-92m7-4fpw-2wxm: Jenkins: Open Redirect phishing attacks possible via "from" parameter in "Delegate to ser…ghsa
More from Jenkins Security Advisories
- unknownJenkins Security Advisory 2026-08-052026-08-05
- unknownJenkins Security Advisory 2026-06-242026-06-24
- unknownJenkins Security Advisory 2026-05-272026-05-27
- unknownJenkins Security Advisory 2026-04-292026-04-29
- unknownJenkins Security Advisory 2026-03-182026-03-18