logo

Critical Jenkins Deserialization Flaw Allows Attackers to Execute Code on Controllers

ID: 9d8dca40-94bd-59a4-a654-ac4fb6f95905

STIX ID: report--9d8dca40-94bd-59a4-a654-ac4fb6f95905

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-08-06

Date Updated: 2026-08-06

Author: Divya

...
...

A critical Jenkins deserialization flaw (CVE-2026-70426 / SECURITY-3911) in the Remoting library can bypass the JEP-200 class filter via a fallback deserialization path, enabling remote code execution on controllers when exploited by a compromised agent or an account with Agent/Connect permissions; affected Remoting builds and Jenkins versions are identified, fixes were released in Jenkins 2.576 and LTS 2.568.2, and administrators are advised to upgrade, restrict agent permissions, apply documented workarounds, and monitor for anomalous Remoting activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.