CVE-2026-70426
Affects Jenkins Core Affects plugin: AWS CodeBuild Affects plugin: CodeSonar Affects plugin: External Workspace Manager Affects plugin: Google Chat Notification Affects plugin: HCL AppScan Affects plugin: Horreum Affects plugin: Ivy Report Affects plugin: Multijob Affects plugin: Parameterized Remote Trigger Affects plugin: Qualys Container Scanning Connector Affects plugin: Sauce OnDemand Affects plugin: SCM-Manager Affects plugin: Summary Display Affects plugin: Violation Comments to GitLab Affects plugin: Webhook Secret Credentials Provider Affects plugin: XML Job to Job DSL
CSIRTS triage
- What
- Multiple vulnerabilities in Jenkins.
- Who is affected
- Jenkins deployments with unpatched versions.
- Urgency
- Requires review of individual CVE details to assess urgency.
- Action
- Apply Jenkins security updates corresponding to the published CVEs.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-70426
Get an email if CVE-2026-70426 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
Advisory coverage (4)
- high[NEW] [high] Jenkins Plugins: Multiple vulnerabilitiescert-bund · 2026-08-06
- unknownJenkins Multiple Vulnerabilitieshkcert · 2026-08-06
- criticalCVE-2026-70426: In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkin…nvd · 2026-08-05
- unknownJenkins Security Advisory 2026-08-05jenkins · 2026-08-05
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-70426)