Jenkins security advisory (AV26-877)

Introduction to Malware Binary Triage (IMBT) Course

Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

  <div>
<div>
        <div><p><strong>Serial Number: </strong>AV26-877<br /><strong>Date: </strong>September 3, 2026</p>

As of September 2, 2026, Jenkins Project is affected by vulnerabilities in the following products:

  • Jenkins
    • ALL except 2.568.3
    • ALL except 2.580
  • Jenkins Allure Plugin
    • Prior to or equal to 2.35.2
  • Jenkins Customizable Header Plugin
    • Prior to or equal to 295.v2544b_ca_19b_97
  • Jenkins File Parameter Plugin
    • Prior to or equal to 425.v3fa_801681b_5e
  • Jenkins GitLab Plugin
    • Prior to or equal to 1.9.16
  • Jenkins LDAP Plugin
    • Prior to or equal to 807.809.vd3a_4e5e4ec98
  • Jenkins Microsoft Entra ID (previously Azure AD) Plugin
    • Prior to or equal to 710.v0b_ff8e9cc2d2
  • Jenkins Parameterized Remote Trigger Plugin
    • Prior to or equal to 3.2.2
  • Jenkins Performance Plugin
    • Prior to or equal to 1015.v09ca_52b_3370e
  • Jenkins Pipeline: Build Step Plugin
    • Prior to or equal to 599.v4b_67ea_11b_152
  • Jenkins SAML Plugin
    • Prior to or equal to 4.618.v441a_27fa_46d2
  • Jenkins Script Security Plugin
    • Prior to or equal to 1412.v7737b_3405f86
  • Jenkins TICS Plugin
    • Prior to or equal to 2025.1.1
  • Jenkins ThinBackup Plugin
    • Prior to or equal to 2.1.4
  • Jenkins XebiaLabs XL Deploy Plugin
    • Prior to or equal to 26.1.0
  • Jenkins update-center2
    • Prior to or equal to 3.18.3

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

</div>

Article Link: Jenkins security advisory (AV26-877) - Canadian Centre for Cyber Security