logo

Critical, Actively Exploited Jenkins RCE Bug Suffers Patch Lag

ID: ad072765-78b6-5624-b1b1-f0d4ae9a58b5

STIX ID: report--ad072765-78b6-5624-b1b1-f0d4ae9a58b5

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-08-20

Date Updated: 2026-05-05

Author: Nate Nelson, Contributing Writer

...
...

A critical Jenkins CLI path traversal vulnerability (CVE-2024-23897, CVSS 9.8) remains actively exploited months after disclosure; despite a security fix, many instances remained unpatched, with public PoCs and automated attacks emerging quickly. Exploitation has led to credential theft, corporate GitHub breaches, source-code exfiltration, and ransomware (including RansomExx) incidents, affecting tens of thousands of exposed Jenkins installations and prompting CISA KEV listing and remediation urgency.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.