A critical vulnerability, CVE-2026-70426, has been identified in Jenkins that allows attackers with Agent/Connect permission to bypass the JEP-200 deserialization filter, enabling remote code execution (RCE) on the controller. This flaw poses a significant risk as it can expose sensitive information within CI/CD pipelines. The vulnerability affects Jenkins versions up to 2.575 (weekly) and 2.568.1 (LTS). Patching is urgent; users should update to Jenkins 2.576 (weekly) or 2.568.2 (LTS).
Additionally, related vulnerabilities include CVE-2026-70427, which allows arbitrary file creation, and CVE-2026-70428, which permits path traversal in file parameters. There are no confirmed exploitations in the wild as of now.