logo

New Critical Jenkins Vulnerabilities Put CI/CD Servers at Risk of RCE Exploits

ID: a2376b8e-0246-5380-84ba-7d76b7df8ea8

STIX ID: report--a2376b8e-0246-5380-84ba-7d76b7df8ea8

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-03-20

Date Updated: 2026-04-22

Author: Divya

...
...

Jenkins published a critical advisory describing multiple vulnerabilities in the core server and the LoadNinja plugin that can lead to arbitrary file creation, credential exposure, and remote code execution—most notably a symlink-based archive extraction flaw (CVE-2026-33001) and a DNS rebinding bypass of CLI WebSocket origin checks (CVE-2026-33002). Administrators are advised to upgrade to Jenkins weekly 2.555 or LTS 2.541.3 and LoadNinja 2.2, enforce authentication, revoke anonymous permissions, and require HTTPS to mitigate exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.