Critical Jenkins Deserialization Flaw Allows Attackers to Execute Code on Controllers
ID: 9d8dca40-94bd-59a4-a654-ac4fb6f95905
STIX ID: report--9d8dca40-94bd-59a4-a654-ac4fb6f95905
Feed Name: GBHackers
A critical Jenkins deserialization flaw (CVE-2026-70426 / SECURITY-3911) in the Remoting library can bypass the JEP-200 class filter via a fallback deserialization path, enabling remote code execution on controllers when exploited by a compromised agent or an account with Agent/Connect permissions; affected Remoting builds and Jenkins versions are identified, fixes were released in Jenkins 2.576 and LTS 2.568.2, and administrators are advised to upgrade, restrict agent permissions, apply documented workarounds, and monitor for anomalous Remoting activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
