Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08

Vendors · jenkins

jenkins

· 70 Critical

Total CVEs

1,772

Critical

70

Products

692

Search All CVEs →

1,772

Products (692)

jenkins276 CVEspipeline\38 CVEsscript security33 CVEsblue ocean11 CVEsemail extension11 CVEsactive directory11 CVEsgit11 CVEsconfiguration as code9 CVEsbuild failure analyzer9 CVEsconfig file provider9 CVEsns-nd integration performance publisher8 CVEscredentials binding8 CVEshtml publisher7 CVEsgithub branch source7 CVEsopenshift deployer7 CVEsopenid connect authentication7 CVEssubversion7 CVEsrundeck7 CVEskubernetes7 CVEsazure vm agents6 CVEsxebialabs xl deploy6 CVEsgerrit trigger6 CVEsazure ad6 CVEsgithub6 CVEsamazon ec26 CVEsgithub pull request builder6 CVEspipeline maven integration6 CVEsgitlab6 CVEsgoogle compute engine6 CVEssaml single sign on6 CVEsproject inheritance6 CVEsrepository connector6 CVEshashicorp vault6 CVEswarnings next generation6 CVEsjob configuration history6 CVEsopenid6 CVEselectricflow6 CVEsdeployment dashboard6 CVEscadence vmanager5 CVEswso2 oauth5 CVEswebsphere deployer5 CVEsactive choices5 CVEssupport core5 CVEsscriptler5 CVEspublish over ssh5 CVEspromoted builds5 CVEsappspider5 CVEsoctoperf load testing5 CVEsneuvector vulnerability scanner5 CVEsmercurial5 CVEsmatrix project5 CVEsmailer5 CVEsmabl5 CVEsjunit5 CVEsjob and node ownership5 CVEsjira5 CVEsgoogle login5 CVEsaws codecommit trigger5 CVEsgit parameter5 CVEsgit client5 CVEsfortify5 CVEsextended choice parameter5 CVEsdelphix5 CVEscode dx5 CVEschef sinatra5 CVEsrole-based authorization strategy4 CVEsansible4 CVEsbitbucket branch source4 CVEsbitbucket oauth4 CVEsbuild-publisher4 CVEscheckmarx4 CVEscompuware topaz for total test4 CVEscons3rt4 CVEscontinuous integration with toad edge4 CVEsconvertigo mobile platform4 CVEscoverity4 CVEscredentials4 CVEscrx content package deployer4 CVEsdeployer framework4 CVEsembeddable build status4 CVEsfortify on demand4 CVEsgitlab authentication4 CVEsgogs4 CVEshealth advisor by cloudbees4 CVEsicescrum4 CVEsjira pipeline steps4 CVEsjob import4 CVEskatalon4 CVEskubernetes ci4 CVEskubernetes continuous deploy4 CVEsliquibase runner4 CVEsmatlab4 CVEsmaven4 CVEsnexus platform4 CVEsorka by macstadium4 CVEsp44 CVEspaaslane estimate4 CVEsproxmox4 CVEsrapiddeploy4 CVEsreport portal4 CVEsrequests4 CVEss3 publisher4 CVEsssh4 CVEsstatic analysis utilities4 CVEssubversion partial release manager4 CVEsteam concert4 CVEsteam foundation server4 CVEsvmware lab manager slaves4 CVEswarnings4 CVEszephyr enterprise test management3 CVEsaudit to database3 CVEsdbcharts3 CVEscode coverage api3 CVEsbuild-metrics3 CVEssynopsys coverity3 CVEsaudit trail3 CVEsautocomplete parameter3 CVEsstorable configs3 CVEscloudbees cd3 CVEssoasta cloudtest3 CVEsgeneric webhook trigger3 CVEssemantic versioning3 CVEsself-organizing swarm modules3 CVEsftp publisher3 CVEsazure credentials3 CVEssaml3 CVEsfolders3 CVEsflaky test handler3 CVEsconjur secrets3 CVEselasticbox ci3 CVEselastest3 CVEsdocker3 CVEsblack duck hub3 CVEsbitbucket server integration3 CVEseasyqa3 CVEsdynatrace application monitoring3 CVEsdotci3 CVEsrqm3 CVEsdynamic extended choice parameter3 CVEsrocketchat notifier3 CVEscas3 CVEstracetronic ecu-test3 CVEsreverse proxy auth3 CVEsrelution enterprise appstore publisher3 CVEsrecipe3 CVEspublish to bitbucket3 CVEsansible tower3 CVEspipeline github notify step3 CVEstestquality updater3 CVEsxpath configuration viewer3 CVEsowasp dependency-check3 CVEsopenstack heat3 CVEsapplitools eyes3 CVEsvsphere3 CVEstestcomplete support3 CVEsaqua security scanner3 CVEsnomad3 CVEsnetsparker cloud scan3 CVEsmatrix authorization strategy3 CVEsxebialabs xl release3 CVEsmac3 CVEscloudbees aws credentials3 CVEslucene-search3 CVEsbeaker builder3 CVEslibvirt slaves3 CVEszephyr for jira test management3 CVEsdashboard view3 CVEskmap3 CVEsdatabase3 CVEsgit changelog2 CVEscluster statistics2 CVEscobertura2 CVEscollabnet2 CVEscompuware ispw operations2 CVEscompuware source code download for endevor\, pds\, and ispw2 CVEscompuware topaz utilities2 CVEscompuware xpediter code coverage2 CVEsvncrecorder2 CVEsconsul kv builder2 CVEsconvert to pipeline2 CVEsvrealize orchestrator2 CVEscoverage\/complexity scatter plot2 CVEsbadge2 CVEscurseforge publisher2 CVEscustom checkbox parameter2 CVEscvs2 CVEsdatadog2 CVEsdead man\'s snitch2 CVEsdebian package builder2 CVEsdelete log2 CVEsdependency graph viewer2 CVEsdeploy weblogic2 CVEsdeployhub2 CVEsazure service fabric2 CVEsdigital.ai app management publisher2 CVEsdingding json pusher2 CVEsdocker-build-step2 CVEsdocker commons2 CVEsdry2 CVEsec22 CVEsecharts api2 CVEsazure key vault2 CVEsexternal monitor job type2 CVEsextra columns2 CVEsfailed job deactivator2 CVEsfavorite2 CVEsfilesystem list parameter2 CVEsfindbugs2 CVEsfitnesse2 CVEsfolder-based authorization strategy2 CVEsagent server parameter2 CVEsfortify on demand uploader2 CVEsfrugal testing2 CVEsgatling2 CVEsgearman2 CVEsgit server2 CVEsgithub oauth2 CVEsaws codedeploy2 CVEsgitlab hook2 CVEsgitlab oauth2 CVEsglobal-build-stats2 CVEsgoogle cloud backup2 CVEsgoogle kubernetes engine2 CVEsgroovy2 CVEsgroovy libraries2 CVEsharvest scm2 CVEsautonomiq2 CVEsimage tag parameter2 CVEsinedo buildmaster2 CVEsinedo proget2 CVEsjclouds2 CVEsjenkins-reviewbot2 CVEsjianliao notification2 CVEswildfly deployer2 CVEsjiratestresultreporter2 CVEswmi windows agents2 CVEsjx resources2 CVEsworksoft execution manager2 CVEskeycloak authentication2 CVEskoji2 CVEskubernetes pipeline2 CVEslambdatest-automation2 CVEsloadninja2 CVEslockable resources2 CVEsm2release2 CVEsassembla auth2 CVEsassembla2 CVEsmashup portlets2 CVEsmask passwords2 CVEsasakusasatellite2 CVEsmatrix reloaded2 CVEsmaven artifact choicelistprovider \(nexus\)2 CVEsmaven metadata2 CVEsmaven repository server2 CVEsmongodb2 CVEsmultijob2 CVEsnested view2 CVEsxl testview2 CVEsnexus task runner2 CVEsnouvola divecloud2 CVEsnunit2 CVEsaqua microscanner2 CVEsoctopusdeploy2 CVEsontrack2 CVEsopenshift login2 CVEsopenshift pipeline2 CVEsopsgenie2 CVEsoracle cloud infrastructure compute classic2 CVEsxooa2 CVEsowasp dependency-track2 CVEsparameterized trigger2 CVEsperfecto2 CVEspipeline aggregator view2 CVEspipeline utility steps2 CVEsplot2 CVEsapica loadtest2 CVEsxray - test management for jira2 CVEspublish over ftp2 CVEsqmetry test management2 CVEsquay.io trigger2 CVEsrabbitmq consumer2 CVEsreadyapi functional testing2 CVEsredgate sql change automation2 CVEsrelease2 CVEsrelease helper2 CVEsrepo2 CVEsandroid lint2 CVEsrequest rename or delete2 CVEsrest list parameter2 CVEs360 fireline2 CVEsanchore container image scanner2 CVEsscm httpclient2 CVEsscp publisher2 CVEsselection tasks2 CVEssensedia api platform tools2 CVEsservicenow devops2 CVEsshelve project2 CVEssidebar link2 CVEssimple queue2 CVEssitemonitor2 CVEsskytap cloud ci2 CVEsslack notification2 CVEssnow commander2 CVEssoapui pro functional testing2 CVEssonar gerrit2 CVEssonargraph integration2 CVEssounds2 CVEsspira importer2 CVEssquash tm publisher2 CVEsssh agent2 CVEsstart windocks container2 CVEsstash branch parameter2 CVEsstatistics gatherer2 CVEsalauda kubernetes support2 CVEssumologic publisher2 CVEsalauda devops pipeline2 CVEsswamp2 CVEstag profiler2 CVEstap2 CVEstemplating engine2 CVEstest results aggregator2 CVEstestlink2 CVEstestng results2 CVEstests selector2 CVEsthemis2 CVEsthreadfix2 CVEstoken macro2 CVEsurltrigger2 CVEsvaddy2 CVEsvalgrind2 CVEsview26 test-reporting2 CVEsviolation comments to gitlab2 CVEsbigpanda notifier2 CVEsbenchmark evaluator2 CVEsbuild notifications2 CVEsbuild with parameters2 CVEsbuildgraph-view2 CVEsbumblebee hp alm2 CVEsbyteguard build actions2 CVEsbearychat2 CVEscisco spark2 CVEsclaim2 CVEscloudbees2 CVEszanata1 CVEskryptowire1 CVEsassembla merge request builder1 CVEsabsint astree1 CVEsxcode integration1 CVEskubernetes credentials provider1 CVEsbazaar1 CVEsbatch task1 CVEsldap email1 CVEslibvirt agents1 CVEscustom job icon1 CVEslightweight directory access protocol1 CVEslink column1 CVEsabsint a31 CVEslist git branches parameter1 CVEsliterate1 CVEsloadcomplete support1 CVEsloader.io1 CVEsstorage configs1 CVEsstructs1 CVEslocked files report1 CVEslog command1 CVEslog parser1 CVEslogstash1 CVEscustom build properties1 CVEsm2 release1 CVEszoho qengine1 CVEszap pipeline1 CVEscurrent versions systems1 CVEsmail commander1 CVEssubversion release manager1 CVEsmantis1 CVEsmarkdown formatter1 CVEsbuild environment1 CVEschosen-views-tabbar1 CVEsmathworks polyspace1 CVEscucumber living documentation1 CVEscryptomove1 CVEsbuild monitor view1 CVEsswarm1 CVEsmattermost1 CVEsmattermost notification1 CVEsxframium builder1 CVEscompuware zadviser api1 CVEssynopsys detect1 CVEscloud statistics1 CVEsmcp server1 CVEsmeliora testlab1 CVEsartifact repository parameter1 CVEsmetrics1 CVEsminio storage1 CVEsmission control1 CVEsbuild pipeline1 CVEsmonitor-remote-job1 CVEsmonitoring1 CVEsmq notifier1 CVEsmsteams webhook trigger1 CVEsmstest1 CVEsmultibranch scan webhook trigger1 CVEsvmware vrealize codestream1 CVEsmultiselect parameter1 CVEsnaginator1 CVEsneoload1 CVEsnerrvana1 CVEscompuware strobe measurement1 CVEswall display1 CVEsaqua security severless scanner1 CVEsteam views1 CVEstelegram bot1 CVEsnode and label parameter1 CVEsnodejs1 CVEscrowd integration1 CVEstemplate workflows1 CVEscrittercism-dsym1 CVEsnuget1 CVEscloudbees docker hub\/registry notification1 CVEsclearcase release1 CVEscompuware common configuration1 CVEsofficial owasp zap1 CVEstestfairy1 CVEsopen stf1 CVEsapprenda1 CVEscrap4j1 CVEsopenid connect provider1 CVEsapplication detector1 CVEsclif performance testing1 CVEscloud foundry1 CVEsopenstack cloud1 CVEscppncss1 CVEsopentelemetry1 CVEscomputer queue1 CVEscloud infrastructure compute1 CVEstestsigma test plan run1 CVEsosf builder suite \1 CVEscppcheck1 CVEscaliper ci1 CVEsxp-dev1 CVEsvs team services continuous deployment1 CVEspackage version1 CVEsparameterized remote trigger1 CVEscall remote job1 CVEsparasoft environment manager1 CVEsparasoft findings1 CVEspegdown formatter1 CVEsthycotic devops secrets vault1 CVEsperfecto mobile1 CVEsperforce1 CVEsperformance1 CVEsperformance publisher1 CVEsperiodic backup1 CVEspersona1 CVEsphabricator differential1 CVEspipeline-input-step1 CVEsapplatix1 CVEsthycotic secret server1 CVEspipeline classpath step1 CVEscoverage1 CVEsappdynamics1 CVEspipeline nodes and processes1 CVEspipeline remote loader1 CVEspipeline restful api1 CVEspipeline supporting apis1 CVEstics1 CVEsplain credentials1 CVEsplay framework1 CVEstimestamper1 CVEspluggable authentication module1 CVEspmd1 CVEspoll scm1 CVEspom2config1 CVEsport allocator1 CVEstinfoil security1 CVEscouchdb-statistics1 CVEspromoted builds \(simple\)1 CVEscloudshare docker-machine1 CVEsprqa1 CVEspublish over cifs1 CVEstrac publisher1 CVEsandroid signing1 CVEscopy to slave1 CVEspuppet enterprise pipeline1 CVEspwauth security realm1 CVEscompact columns1 CVEsquality gates1 CVEsqualys web app scanning connector1 CVEstranslation assistance1 CVEsqueue cleanup1 CVEstuleap authentication1 CVEsradargun1 CVEsradiator view1 CVEsrandom string parameter1 CVEsxunit1 CVEsreadonly parameter1 CVEstuleap git branch source1 CVEsrebuilder1 CVEscopy data to workspace1 CVEsred hat dependency analytics1 CVEsturboscript1 CVEsredpen - pipeline reporter for jira1 CVEstwitter1 CVEsupdate-center21 CVEscopy artifact1 CVEsremote-jobs-view1 CVEsupload to pgyer1 CVEsreport info1 CVEsyaml axis1 CVEscccc1 CVEsusemango runner1 CVEsyet another build visualizer1 CVEsresource disposer1 CVEsuser1st utester1 CVEscopr1 CVEsrhnpush-plugin1 CVEsrich text publisher1 CVEsrobot framework1 CVEscontrast continuous application security1 CVEsccm1 CVEsrpmsign-plugin1 CVEsvncviewer1 CVEsvmware vrealize automation1 CVEss3 explorer1 CVEsyoutrack-plugin1 CVEssaltstack1 CVEssametime1 CVEsconfluence publisher1 CVEssaml single sign-on1 CVEsanchorchain1 CVEssauce ondemand1 CVEsvalidating email parameter1 CVEsvalidating string parameter1 CVEsscreenrecorder1 CVEsamazon web services serverless application model1 CVEsamazon sns build notifier1 CVEssctmexecutor1 CVEssecurity inspector1 CVEsvboxwrapper1 CVEsselenium1 CVEsselenium html report1 CVEsconfiguration slicing1 CVEsbart1 CVEsveracode-scanner1 CVEsserena sra deploy1 CVEsvfabric application director1 CVEsshared library version override1 CVEsshared objects1 CVEsdoktor1 CVEseagle tester1 CVEsdocker swarm1 CVEsview-cloner1 CVEsshortcut job1 CVEsecx copy data management1 CVEsedgewall trac1 CVEseggplant1 CVEseggplant runner1 CVEseiffel broadcaster1 CVEsdistributed fork1 CVEsdingtalk1 CVEselasticsearch query1 CVEsazure publishersettings credentials1 CVEseloyente1 CVEscheckstyle1 CVEsemail extension template1 CVEszulip1 CVEsenvironment dashboard1 CVEsazure event grid notifier1 CVEsextensible choice parameter1 CVEsextensive testing1 CVEschef identity1 CVEssimple travis pipeline runner1 CVEsextreme-feedback1 CVEsextreme feedback panel1 CVEsfabric beta publisher1 CVEsviolations1 CVEsskype notifier1 CVEsfavorite plugin1 CVEsfavorite view1 CVEsfile parameters1 CVEsfile system scm1 CVEsfiles found trigger1 CVEsvisual expert1 CVEsfilesystem trigger1 CVEsbitbucket approve1 CVEsslack upload1 CVEsdingding1 CVEsfogbugz1 CVEssmalltest1 CVEsdigitalocean1 CVEsdiawi upload1 CVEsfortify cloudscan1 CVEssms notification1 CVEsvisual studio code metrics1 CVEsvisualworks store1 CVEsdescription column1 CVEsconfig rotator1 CVEssofy.ai1 CVEsgem publisher1 CVEswalti1 CVEsazure container service1 CVEsazure cli1 CVEsdeploy1 CVEsawseb deployment1 CVEsaws global configuration1 CVEsbitbucket push and pull request1 CVEsgitbucket1 CVEsaws elastic beanstalk publisher1 CVEsgithub authentication1 CVEsaws codepipeline1 CVEsgithub coverage reporter1 CVEssonar quality gates1 CVEscodescan1 CVEsgithub pull request coverage status1 CVEsaws codebuild1 CVEswarrior framework1 CVEscodefresh integration1 CVEsgitlab logo1 CVEssource code management filter jervis1 CVEssourcegear vault1 CVEsglobal build stats1 CVEsglobal post script1 CVEsglobal variable string parameter1 CVEsaccurev1 CVEsgoogle-play-android-publisher1 CVEsgoogle calendar1 CVEssourcemonitor1 CVEsaws cloudwatch logs publisher1 CVEsspeaks\!1 CVEsaws-device-farm1 CVEsgoogle oauth credentials1 CVEsgradle1 CVEscloudcoreo deploytime1 CVEssplunk1 CVEsgroovy postbuild1 CVEsspring config1 CVEsavatar1 CVEsweibo1 CVEshidden parameter1 CVEshockeyapp1 CVEshpe network virtualization1 CVEssqlplus script runner1 CVEshtml resource1 CVEshttp request1 CVEshyper.sh commons1 CVEsibm application security on cloud1 CVEsibm cloud devops1 CVEswhite source1 CVEsifttt build notifier1 CVEsimage gallery1 CVEsbmc release package and deployment1 CVEsimplied labels1 CVEsincapptic connect uploader1 CVEsz\/os connector1 CVEsssh-agent1 CVEsinstallation manager tool1 CVEsinstant-messaging1 CVEsirc1 CVEsivy1 CVEsjabber \(xmpp\) notifier and control1 CVEsjabber server1 CVEsjacoco1 CVEsjapex1 CVEsssh-slave1 CVEsjdepend1 CVEsjdk parameter1 CVEsbacklog1 CVEsjenkins-cloudformation-plugin1 CVEsssh2 easy1 CVEsbrakeman1 CVEsjigomerge1 CVEsauthorize project1 CVEsjira-ext1 CVEsjira issue updater1 CVEsssh credentials1 CVEsssh slaves1 CVEsjms messaging1 CVEsdelivery pipeline1 CVEsdate parameter1 CVEsjob dsl1 CVEsjob generator1 CVEsstack hammer1 CVEsjsgames1 CVEsassociated files1 CVEsbuckminster1 CVEskanboard1 CVEsstarteam1 CVEsbugzilla1 CVEskiuwan1 CVEsklaros-testmanagement1 CVEsklocwork analysis1 CVEsdata theorem mobile app security1 CVEs

Recent Vulnerabilities

View all 1,772
CVE-2026-53442MEDIUM 5.3

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before storing them in job configurations unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system.

CVE-2026-53441MEDIUM 5.4

Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of a generic offline cause that could be set through the `POST config.xml` API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.

CVE-2026-53440MEDIUM 4.3

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet container" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled domain.

CVE-2026-53439MEDIUM 4.3

Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permission to determine other users' configured timezone and to enumerate view names of other users' "My Views".

CVE-2026-53438MEDIUM 4.3

A missing permission check in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allows attackers with Item/Cancel permission, but lacking Item/Read permission, to cancel queue items they do not have permission to view.

CVE-2026-53437MEDIUM 4.3

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains tab or newline characters between `//`, allowing attackers to perform phishing attacks.

CVE-2026-53436MEDIUM 4.3

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains relative path segments (`./` or `../`), allowing attackers to perform phishing attacks.

CVE-2026-53435HIGH 8.8

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards. This can be used to impersonate any user and send HTTP requests on their behalf, up to and including use of the Script Console to run arbitrary code, or to read arbitrary files from the Jenkins controller.

CVE-2026-9674MEDIUM 4.3

A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 662.vd2e0001f6b_b_d and earlier allows attackers to resume failed Multijob builds.

CVE-2026-48927MEDIUM 5.5

Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs or views.

CVE-2026-48924MEDIUM 4.3

Jenkins Bitbucket OAuth Plugin 0.17 and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

CVE-2026-48923MEDIUM 4.3

Jenkins AppSpider Plugin 1.0.17 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to connect to an attacker-specified URL.

CVE-2026-48922HIGH 7.5

Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file and zip file credentials, allowing attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem, which can lead to remote code execution if Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used for a job running on the built-in node.

CVE-2026-48921HIGH 7.5

Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing attackers able to control the content of a library used by a Pipeline job to read arbitrary files on the Jenkins controller filesystem.

CVE-2026-48920HIGH 8.8

Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by setting the `data-inline` attribute, without restrictions on the image URLs that can be inlined, allowing attackers able to control the email content to specify `file:` URLs for images to read arbitrary files from the Jenkins controller filesystem.

CVE-2026-48919MEDIUM 6.6

Jenkins Active Directory Plugin 2.41 and earlier deserializes data from LDAP referrals without validation.

CVE-2026-48918MEDIUM 6.6

Jenkins Active Directory Plugin 2.41 and earlier follows LDAP referrals by default.

CVE-2026-42525MEDIUM 4.3

Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.

CVE-2026-42524HIGH 8.0

Jenkins HTML Publisher Plugin 427 and earlier does not escape job name and URL in the legacy wrapper file, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

CVE-2026-42523CRITICAL 9.0

Jenkins GitHub Plugin 1.46.0 and earlier improperly processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITScm polling", resulting in a stored cross-site scripting (XSS) vulnerability exploitable by non-anonymous attackers with Overall/Read permission.

CVE-2026-42522MEDIUM 4.3

A missing permission check in Jenkins GitHub Branch Source Plugin 1967.vdea_d580c1a_b_a_ and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL with attacker-specified GitHub App credentials.

CVE-2026-42521MEDIUM 6.5

Jenkins Matrix Authorization Strategy Plugin 2.0-beta-1 through 3.2.9 (both inclusive) invokes parameterless constructors of classes specified in configuration when deserializing inheritance strategies, without restricting the classes that can be instantiated, allowing attackers with Item/Configure permission to instantiate arbitrary types, which may lead to information disclosure or other impacts depending on the classes available on the classpath.

CVE-2026-42520HIGH 7.5

Jenkins Credentials Binding Plugin 719.v80e905ef14eb_ and earlier does not sanitize file names for file and zip file credentials, allowing attackers able to provide credentials to a job to write files to arbitrary locations on the node filesystem, which can lead to remote code execution if Jenkins is configured to allow a low-privileged user to configure file or zip file credentials used for a job running on the built-in node.

CVE-2026-42519MEDIUM 4.3

A missing permission check in Jenkins Script Security Plugin 1399.ve6a_66547f6e1 and earlier allows attackers with Overall/Read permission to enumerate pending and approved Script Security classpaths.

CVE-2026-33004MEDIUM 4.3

Jenkins LoadNinja Plugin 2.1 and earlier does not mask LoadNinja API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.