logo

CISA warns of Jenkins RCE bug exploited in ransomware attacks

ID: c84e4282-3198-5160-bb06-35912299bd6e

STIX ID: report--c84e4282-3198-5160-bb06-35912299bd6e

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2024-08-19

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CVE-2024-23897 is a critical Jenkins flaw in the args4j CLI parser (expandAtFiles) enabling unauthenticated file reads and potential RCE; multiple PoCs and active exploitation have been observed, thousands of exposed Jenkins instances remain unpatched, and threat actors including IntelBroker and RansomEXX have used the vulnerability in breaches and ransomware operations, prompting CISA to add it to the Known Exploited Vulnerabilities catalog and mandate remediation for federal agencies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.