CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-70440

highCVSS 5.4covered by 3 sourcesfirst seen 2026-08-05
An attacker can exploit multiple vulnerabilities in Jenkins to execute arbitrary code, escalate privileges, bypass security measures, disclose confidential information, manipulate data as well as perform cross-site scripting (XSS) or server-side request forgery (SSRF) attacks.

CSIRTS triage

What
Multiple unspecified vulnerabilities affect Jenkins Core and 15 associated plugins.
Who is affected
Deployments of Jenkins Core and users of AWS CodeBuild, CodeSonar, External Workspace Manager, Google Chat Notification, HCL AppScan, Horreum, Ivy Report, Multijob, Parameterized Remote Trigger, Qualys Container Scanning Connector, Sauce OnDemand, SCM-Manager, Summary Display, Violation Comments to GitLab, and Webhook Secret Credentials Provider plugins.
Urgency
Severity unknown; eight CVEs assigned indicate multiple impact vectors requiring immediate investigation.
Action
Consult Jenkins Security Advisory 2026-08-05 for specific vulnerability details and apply recommended patches for Core and affected plugins.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-70440

Get an email if CVE-2026-70440 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (3)

External references

NVD record for CVE-2026-70440

CVE.org record

Embed the live status

CVE-2026-70440 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-70440 status](https://www.csirts.com/badge/CVE-2026-70440)](https://www.csirts.com/cve/CVE-2026-70440)