CVE Tools
Back to feed
Exploited in the wild Jenkins (controllers) rce Jenkins auth-bypass

Jenkins RCE Vulnerability CVE-2026-53435 Now Under Active Exploitation

Daily CyberSecurity (securityonline.info)·By Do Son··2 min read
CVE Tools coverage

Attackers are actively exploiting a critical remote code execution flaw in Jenkins, tracked as CVE-2026-53435. The issue allows adversaries to run arbitrary code on Jenkins controllers, including impersonating users and reaching the Script Console to execute commands or access sensitive files. Jenkins users on Jenkins 2.567 and earlier, as well as LTS 2.555.2 and earlier, should patch immediately; the same advisory also addresses open-redirect issues CVE-2026-53436 and CVE-2026-53437, though they are less severe.