Jenkins security advisory (AV26-782)

Serial number: AV26-782
Date: August 6, 2026

As of August 5, 2026, Jenkins Project is affected by vulnerabilities in the following products:

  • Jenkins
    • ALL except 2.568.2
    • ALL except 2.576
  • Jenkins AWS CodeBuild Plugin
    • Prior to or equal to 0.59
  • Jenkins CodeSonar Plugin
    • Prior to or equal to 3.6.0
  • Jenkins Google Chat Notification Plugin
    • Prior to or equal to 166.ve6b_de280f2e8
  • Jenkins Horreum Plugin
    • Prior to or equal to 0.16.162.v33b_4a_a_b_5f828
  • Jenkins Ivy Report Plugin
    • Prior to or equal to 1.2
  • Jenkins Multijob Plugin
    • Prior to or equal to 669.v9d96a_d9c71b_0
  • Jenkins Violation Comments to GitLab Plugin
    • Prior to or equal to 2.62.0
  • Jenkins XML Job to Job DSL Plugin
    • Prior to or equal to 0.1.13
  • Remoting
    • ALL except 3355.3357.v931d3c992987
    • ALL except 3385.vf1123fb_515da_

The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.

Date modified: