Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Jenkins Flaw Enables Malicious Code Execution

Critical Jenkins Flaw Enables Malicious Code Execution

Posted on August 6, 2026 By CWS

Jenkins has identified a significant security flaw that permits attackers to run malicious code on controllers by circumventing a security filter designed for agent-to-controller communication.

Details of the Security Vulnerability

Known as CVE-2026-70426, this vulnerability affects Jenkins setups with specific versions of the Remoting library. It has been classified with a Critical CVSS severity score. Jenkins versions 2.575 and earlier, along with Jenkins LTS 2.568.1 and earlier, are susceptible. The flaw is present in Remoting versions up to 3384.v60d89463d9e0, excluding version 3355.3357.v931d3c992987.

The Remoting library, often distributed as agent.jar or remoting.jar, facilitates communication between the main Jenkins controller and its build agents. These interactions depend on serialized Java objects. Potential Java deserialization vulnerabilities can lead to arbitrary code execution, prompting Jenkins to employ the JEP-200 class filter to screen objects received over a Remoting channel.

Exploitation of the Vulnerability

The JEP-200 filter aims to prevent unsafe classes from being deserialized by the Jenkins controller. However, researchers discovered it was not applied when classes were resolved through a fallback mechanism in the Remoting deserialization process. This oversight allows for a filter bypass.

An attacker with control over an agent process or possessing the Jenkins Agent/Connect permission can exploit this flaw to deserialize Java classes that should be blocked, potentially executing malicious code on the Jenkins controller. This controller is a critical system within a Jenkins environment, and its compromise could expose sensitive information like source code, secrets, and software supply chain pipelines.

Mitigation and Recommendations

Jenkins has addressed the issue in advisory SECURITY-3911, releasing updates Jenkins 2.576 and Jenkins LTS 2.568.2 to ensure the JEP-200 class filter is applied correctly, even in fallback paths. Organizations are urged to upgrade to these versions immediately.

Security teams should evaluate permissions for users and systems with Agent/Connect access and consider isolating untrusted build agents. Jenkins also provided a temporary workaround in its SECURITY-3911-3930 GitHub repository for environments unable to update immediately. Administrators should implement this mitigation cautiously and prioritize upgrading to patched versions.

This vulnerability was disclosed through the European Commission’s Jenkins Bug Bounty Program, underscoring the importance of active security monitoring and prompt response to potential threats.

Cyber Security News Tags:agent-to-controller, bug bounty, code execution, CVE-2026-70426, Cybersecurity, Deserialization, Jenkins, JEP-200 filter, Remoting library, Security, security patch, Software Security, software update, Vulnerability

Post navigation

Previous Post: AI Browser Vulnerabilities: Risks of Claude and ChatGPT Atlas
Next Post: Apple iCloud Private Relay Vulnerability Exposes IPs

Related Posts

Russian Nationals Charged in M Cybercrime Case Russian Nationals Charged in $62M Cybercrime Case Cyber Security News
Hacker Pleads Guilty For Stealing Supreme Court Documents and Leaking via Instagram Hacker Pleads Guilty For Stealing Supreme Court Documents and Leaking via Instagram Cyber Security News
Critical ServiceNow RCE Vulnerability Addressed Critical ServiceNow RCE Vulnerability Addressed Cyber Security News
Claude’s New Feature Simplifies AI Memory Transfer Claude’s New Feature Simplifies AI Memory Transfer Cyber Security News
Huge Surge in Fake Investment Platforms Mimic Forex Exchanges Steal Logins Huge Surge in Fake Investment Platforms Mimic Forex Exchanges Steal Logins Cyber Security News
Critical GNU Guix Vulnerabilities Permit Remote Attacks Critical GNU Guix Vulnerabilities Permit Remote Attacks Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Atlassian Rovo Vulnerable to Data Exfiltration Risks
  • Critical Metabase Flaw Exploited, Urgent Patch Released
  • OpenAI Delays Astra AI Model to Address Cybersecurity Risks
  • UNC6671 Cyber Threat Intensifies with Vishing Attacks
  • ChainDrop Worm Targets npm Packages for Credential Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Atlassian Rovo Vulnerable to Data Exfiltration Risks
  • Critical Metabase Flaw Exploited, Urgent Patch Released
  • OpenAI Delays Astra AI Model to Address Cybersecurity Risks
  • UNC6671 Cyber Threat Intensifies with Vishing Attacks
  • ChainDrop Worm Targets npm Packages for Credential Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark