Jenkins released security updates in Jenkins 2.576 and LTS 2.568.2 to address multiple vulnerabilities, including CVE-2026-70426, a critical Remoting deserialization filter bypass that can let agent processes, code running on agents, or users with Agent/Connect permission bypass JEP-200 protections and potentially achieve code execution on the controller. The advisory also covers core flaws that can enable arbitrary file write leading to controller code execution, an impersonation issue tied to case-insensitive usernames and groups, and unsafe project naming strategy object instantiation. Jenkins said the Remoting issue affects Jenkins 2.575 and earlier and LTS 2.568.1 and earlier, and was fixed in Remoting 3385.vf1123fb_515da_.
The same advisory disclosed serious plugin vulnerabilities, led by CVE-2026-70431 and CVE-2026-70432 in the Multijob Plugin, where Groovy scripting and a CSRF weakness can allow users with Item/Create or Item/Configure permissions to execute arbitrary code in the Jenkins controller JVM. Additional plugin issues include credential enumeration and capture paths, unauthorized workspace file access, a timing side channel in Webhook Secret Credentials Provider Plugin, stored XSS, misuse of system-scoped credentials, and an XXE flaw in Ivy Report Plugin. Jenkins also warned that several plugin vulnerabilities had no fix available at publication time, affecting plugins including AWS CodeBuild, CodeSonar, Google Chat Notification, Horreum, Ivy Report, Parameterized Remote Trigger, Qualys Container Scanning Connector, Sauce OnDemand, Summary Display, Violation Comments to GitLab, and XML Job to Job DSL.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
A CVE record was newly received for CVE-2026-70432, a CSRF vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier. The flaw stems from a form validation endpoint not requiring POST requests and can lead to arbitrary code execution in the Jenkins controller JVM.
A CVE record was newly received for CVE-2026-70431, covering an arbitrary code execution flaw in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier caused by Groovy scripting features not integrating with Script Security Plugin. The issue allows attackers with Item/Create or Item/Configure permission to execute code in the Jenkins controller JVM.
A CVE record was published for CVE-2026-70426, a critical Jenkins Remoting deserialization filter bypass affecting Remoting 3384.v60d89463d9e0 and earlier, as included in Jenkins 2.575 and earlier and LTS 2.568.1 and earlier. Jenkins lists fixes in Jenkins 2.576, Jenkins LTS 2.568.2, and Remoting 3385.vf1123fb_515da_.
Jenkins published a security advisory announcing fixes in Jenkins 2.576, Jenkins LTS 2.568.2, and several plugins including External Workspace Manager, HCL AppScan, Multijob, SCM-Manager, and Webhook Secret Credentials Provider. The advisory also disclosed multiple unresolved plugin vulnerabilities for which no fixes were available at publication time.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcecybersecuritynews.com
Open sourceacn.gov.it
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.