logo

Critical Jenkins Vulnerability Allows Attackers to Execute Malicious Code on Controller

ID: 098af217-ea25-5466-977e-a0a2b33fe167

STIX ID: report--098af217-ea25-5466-977e-a0a2b33fe167

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-08-06

Date Updated: 2026-08-06

Author: Abinaya

...
...

Jenkins disclosed a critical remote code execution vulnerability (CVE-2026-70426) in the Remoting library that can bypass the JEP-200 deserialization filter when classes are resolved via a fallback path; agents or users with Agent/Connect permission could exploit it to run code on the controller. Affected versions include Jenkins 2.575 and earlier (LTS 2.568.1 and earlier) and Remoting versions 3384.v60d89463d9e0 and earlier (with exceptions); fixes were released in Jenkins 2.576 and LTS 2.568.2, and administrators are advised to upgrade, restrict Agent/Connect access, isolate untrusted agents, and apply provided workarounds only as temporary measures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.