Jenkins security advisory (AV26-877)
MediumCanadian Centre for Cyber Security · Canadian Centre for Cyber Security·
As of September 2, 2026, Jenkins Project is affected by vulnerabilities in the following products:
- Jenkins
- ALL except 2.568.3
- ALL except 2.580
- Jenkins Allure Plugin
- Prior to or equal to 2.35.2
- Jenkins Customizable Header Plugin
- Prior to or equal to 295.v2544b_ca_19b_97
- Jenkins File Parameter Plugin
- Prior to or equal to 425.v3fa_801681b_5e
- Jenkins GitLab Plugin
- Prior to or equal to 1.9.16
- Jenkins LDAP Plugin
- Prior to or equal to 807.809.vd3a_4e5e4ec98
- Jenkins Microsoft Entra ID (previously Azure AD) Plugin
- Prior to or equal to 710.v0b_ff8e9cc2d2
- Jenkins Parameterized Remote Trigger Plugin
- Prior to or equal to 3.2.2
- Jenkins Performance Plugin
- Prior to or equal to 1015.v09ca_52b_3370e
- Jenkins Pipeline: Build Step Plugin
- Prior to or equal to 599.v4b_67ea_11b_152
- Jenkins SAML Plugin
- Prior to or equal to 4.618.v441a_27fa_46d2
- Jenkins Script Security Plugin
- Prior to or equal to 1412.v7737b_3405f86
- Jenkins TICS Plugin
- Prior to or equal to 2025.1.1
- Jenkins ThinBackup Plugin
- Prior to or equal to 2.1.4
- Jenkins XebiaLabs XL Deploy Plugin
- Prior to or equal to 26.1.0
- Jenkins update-center2
- Prior to or equal to 3.18.3
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Reproduced in full under licence from Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.
Read at cyber.gc.ca ↗Official Source
At a glance
- Severity
- Mediumfrom category and source signals; no CVSS referenced
- Exploitation
- No vulnerabilities referenced
- Vulnerabilities
- None referenced
- Vendors & products
- Microsoft, GitLab, Jenkins
- Threat actors & malware
- None named
- Industries
- Not industry-specific
- Coverage
- 1 outlet· first seen 2026-09-03 13:54 UTC
- Priority
- 42/100Source tier, category, exploitation and corroboration. Not a risk score for your environment.
Coverage
One outlet has carried this so far.
2026-09-03 13:54 UTC
Related stories
- OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
The Hacker News · 2026-09-12
- GitLab security advisory (AV26-917)
Canadian Centre for Cyber Security · 2026-09-11
- n8n security advisory (AV26-916)
Canadian Centre for Cyber Security · 2026-09-11
- Progress security advisory (AV26-915)
Canadian Centre for Cyber Security · 2026-09-11
- CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
Dark Reading · 2026-09-11