LIVE · cybersecurity feed
Live wire
vendor

Jenkins

12 CVEs published in the last four months and 1 stories. Exploited flaws first.

Critical0
High10
Medium2
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-573018.8highofficial owasp zapJenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the ass73d ago
CVE-2026-572808.8highscript securityJenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied t73d ago
CVE-2026-534358.8highjenkinsIn Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize ar87d ago
CVE-2026-330018.8highjenkinsJenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of 171d ago
CVE-2026-489208.8highemail extensionJenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content 101d ago
CVE-2026-330027.5highjenkinsJenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin val171d ago
CVE-2026-489217.5highpipeline\Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in sh101d ago
CVE-2026-489227.5highcredentials bindingJenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file a101d ago
CVE-2026-572817.5highscript securityJenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotation73d ago
CVE-2026-573037.1highassemblaJenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) att73d ago
CVE-2026-330034.3mediumloadninjaJenkins LoadNinja Plugin 2.1 and earlier stores LoadNinja API keys unencrypted in job config.xml files on the Jenk171d ago
CVE-2026-330044.3mediumloadninjaJenkins LoadNinja Plugin 2.1 and earlier does not mask LoadNinja API keys displayed on the job configuration form,171d ago

Filter the full tracker by Jenkins

Our coverage of Jenkins

awshigh

From CI/CD to Cloud Data: How Shai Hulud Persistence Leads to Redshift Breach

A security incident involving Shai Hulud has been detailed, starting with a compromise in the CI/CD pipeline that led to the exposure of Jenkins credentials. This initial breach allowed for privilege escalation within AWS, ultimately resulting in unauthorized access to Redshift data.