logo

Critical RCE Vulnerability in Jenkins Exploited in the Wild

ID: 7a572e5c-086b-5e36-8cde-69ce57cc585c

STIX ID: report--7a572e5c-086b-5e36-8cde-69ce57cc585c

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-06-17

Date Updated: 2026-06-21

...
...

A critical remote code execution vulnerability (CVE-2026-53435) has been disclosed in Jenkins versions 2.567 and earlier (including LTS 2.555.2 and earlier). The flaw stems from insecure deserialization of an attacker-controlled config.xml, enabling impersonation and arbitrary code execution by unauthenticated or low-privileged actors. Active exploitation has been confirmed; organizations are urged to patch immediately and increase monitoring as advised by authorities including the Centre for Cybersecurity Belgium.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.