CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

[NEW] [high] Jenkins Plugins: Multiple vulnerabilities

highCVE-2026-70426CVE-2026-70427CVE-2026-70428CVE-2026-70429CVE-2026-70430CVE-2026-70431
An attacker can exploit multiple vulnerabilities in Jenkins to execute arbitrary code, escalate privileges, bypass security measures, disclose confidential information, manipulate data as well as perform cross-site scripting (XSS) or server-side request forgery (SSRF) attacks.

CSIRTS triage

What
Multiple vulnerabilities in Jenkins plugins enable remote code execution, privilege escalation, authentication bypass, information disclosure, and SSRF attacks.
Who is affected
All Jenkins installations using affected plugins are at risk.
Urgency
High severity with multiple attack vectors including unauthenticated RCE; immediate patching is critical.
Action
Update all Jenkins plugins to patched versions; identify and list which specific plugins are affected and their version numbers from Jenkins security advisories.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Plugins

Get an email when a new Plugins advisory drops — max one per day, one-click unsubscribe.

Details

Source
CERT-Bund (BSI) Security Advisories (DE · national-cert · site)
Severity
high
Published
2026-08-06
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2665

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-70426coverage & exploitation statusNVD · CVE.org
CVE-2026-70427coverage & exploitation statusNVD · CVE.org
CVE-2026-70428coverage & exploitation statusNVD · CVE.org
CVE-2026-70429coverage & exploitation statusNVD · CVE.org
CVE-2026-70430coverage & exploitation statusNVD · CVE.org
CVE-2026-70431coverage & exploitation statusNVD · CVE.org
CVE-2026-70432coverage & exploitation statusNVD · CVE.org
CVE-2026-70433coverage & exploitation statusNVD · CVE.org
CVE-2026-70434coverage & exploitation statusNVD · CVE.org
CVE-2026-70435coverage & exploitation statusNVD · CVE.org
CVE-2026-70436coverage & exploitation statusNVD · CVE.org
CVE-2026-70437coverage & exploitation statusNVD · CVE.org
CVE-2026-70438coverage & exploitation statusNVD · CVE.org
CVE-2026-70439coverage & exploitation statusNVD · CVE.org
CVE-2026-70440coverage & exploitation statusNVD · CVE.org
CVE-2026-70441coverage & exploitation statusNVD · CVE.org
CVE-2026-70442coverage & exploitation statusNVD · CVE.org
CVE-2026-70443coverage & exploitation statusNVD · CVE.org
CVE-2026-70444coverage & exploitation statusNVD · CVE.org
CVE-2026-70445coverage & exploitation statusNVD · CVE.org
CVE-2026-70446coverage & exploitation statusNVD · CVE.org
CVE-2026-70447coverage & exploitation statusNVD · CVE.org
CVE-2026-70448coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Jenkins Plugins

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from CERT-Bund (BSI) Security Advisories