Critical RCE Vulnerability in Jenkins Exploited in the Wild
ID: 7a572e5c-086b-5e36-8cde-69ce57cc585c
STIX ID: report--7a572e5c-086b-5e36-8cde-69ce57cc585c
Feed Name: ThreatCluster
A critical remote code execution vulnerability (CVE-2026-53435) has been disclosed in Jenkins versions 2.567 and earlier (including LTS 2.555.2 and earlier). The flaw stems from insecure deserialization of an attacker-controlled config.xml, enabling impersonation and arbitrary code execution by unauthenticated or low-privileged actors. Active exploitation has been confirmed; organizations are urged to patch immediately and increase monitoring as advised by authorities including the Centre for Cybersecurity Belgium.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
