logo

45k Jenkins servers exposed to RCE attacks using public exploits

ID: 757fd9e9-c63e-5047-a76e-7b01f0713dae

STIX ID: report--757fd9e9-c63e-5047-a76e-7b01f0713dae

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2024-01-29

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Researchers disclosed CVE-2024-23897 — a critical Jenkins flaw that allows arbitrary file reads via the CLI’s '@' file substitution and can lead to remote code execution; public PoCs exist, Shadowserver reports roughly 45,000 unpatched Internet-exposed instances (majority in China and the US), and vendor patches/mitigations have been released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.