Jenkins released security updates for multiple vulnerabilities in its CI/CD automation platform, including six high-severity flaws involving remote code execution, security-restriction bypass, tampering, and spoofing. Jenkins core versions 2.579 and earlier, and LTS versions 2.568.2 and earlier, are affected; fixed releases are 2.580 and 2.568.3, respectively.
The advisory also identifies vulnerabilities in update-center2 and numerous plugins, including Allure, GitLab, LDAP, SAML, and Script Security. The Canadian Centre for Cyber Security, Italy's ACN/CSIRT, and bjCSIRT urged administrators to review the Jenkins security bulletin, update core installations and affected plugins, and prioritize exposed or internet-accessible Jenkins servers.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security published advisory AV26-877 covering the Jenkins vulnerabilities and advised users and administrators to review the Jenkins security advisory and apply available updates.
FreeBSD published a security update for its Jenkins and Jenkins LTS packages addressing 13 vulnerabilities, CVE-2026-84645 through CVE-2026-84657. The associated Tenable check reported no known exploits and assesses affected hosts through local FreeBSD package inventory checks.
Jenkins Project reported vulnerabilities affecting Jenkins core, update-center2, and numerous plugins. Affected core releases include Jenkins 2.579 and earlier and LTS 2.568.2 and earlier; fixed core versions are 2.580 and 2.568.3, while six issues were rated high severity and included remote code execution, security-restriction bypass, tampering, and spoofing.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
csirt.bj
Open sourceacn.gov.it
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.