Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.2 MEDIUM
CVE-2026-84657 — Jenkins Build CLI Improper Authorization

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flag to cancel a build triggered to wait for completion, allow…

jenkins | Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
4.3 MEDIUM
CVE-2026-84656 — Jenkins Information Disclosure Vulnerability

A missing permission check in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier allows attackers with Item/Read permission on at least one job to read build parameter names and values of jobs they h…

jenkins | Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
4.3 MEDIUM
CVE-2026-84655 — Jenkins JSON and Python API Injection Vulnerability

Jenkins 2.579 and earlier, LTS 2.568.2 and earlier does not escape map keys when serializing objects as JSON and Python through its REST API, allowing attackers able to control map property names to …

jenkins | Remote | Injection
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
5.4 MEDIUM
CVE-2026-84654 — Stapler Form Data Binding Static Field Injection

In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, form data binding allows setting public static fields of t…

jenkins | Remote | Misconfiguration
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2026-84653 — Jenkins Appearance Configuration Improper Authorization

Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform permission checks in the Appearance configuration page, allowing attackers with O…

jenkins | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
0.0 NA
CVE-2026-84652 — Jenkins Session Fixation Vulnerability

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a user is authenticated via the "remember me" cookie, allowing attackers able to serve content on the s…

jenkins | Authentication
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
6.3 MEDIUM
CVE-2026-84651 — Jenkins Agent Configuration Improper Access Control

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the REST API and CLI endpoints for updating agent configuration do not prevent a submitted configuration from overwriting a different agent by s…

jenkins | Remote | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.8 HIGH
CVE-2026-84650 — Jenkins Deserialization Vulnerability

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, transient fields cannot be excluded from deserialization, allowing attackers able to submit configuration updates to specify the values of trans…

jenkins | Remote | Injection
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.8 HIGH
CVE-2026-84649 — Stapler Cross-Site Request Forgery Vulnerability

In Stapler 1839.ved17667b_a_eb_5 through 2107.v8dfcb_e8ed317 (both inclusive), except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.447 through 2.579 (both inclusive), LTS 2.452.1 through 2.568.2 (…

jenkins | Remote | Cross-Site Request Forgery
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.8 HIGH
CVE-2026-84648 — Jenkins System Log Viewer Stored Cross-Site Scripting

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the system log viewer does not escape log record metadata (source, level, and timestamp) resulting in a stored cross-site scripting (XSS) vulner…

jenkins | Remote | Cross-Site Scripting
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.8 HIGH
CVE-2026-84647 — Stapler Arbitrary Object Instantiation Vulnerability

In Stapler 2107.v8dfcb_e8ed317 and earlier, except 2088.2093.vd7c3e58008a_6, included in Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Stapler does not restrict the types of objects that can be…

jenkins | Remote | Misconfiguration
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
4.3 MEDIUM
CVE-2026-84646 — Jenkins User Object Injection Vulnerability

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, user objects can appear as nested field values in other deserialized XML objects, allowing attackers with Overall/Read permission to create user…

jenkins | Remote | Misconfiguration
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.8 HIGH
CVE-2026-84645 — Jenkins Remote Code Execution via Stapler Configuration Injection

In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such as the global configuration…

jenkins | Remote | Misconfiguration
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
9.2 CRITICAL
CVE-2026-78689 — NGINX JavaScript XML Module Out-of-Bounds Write Vulnerability

Description NGINX JavaScript (njs) has a vulnerability in the XML module's namespace prefix list parser, reachable through the xml.exclusiveC14n() method. An unauthenticated remote attacker can tri…

njs | Remote | Memory Corruption
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
7.8 HIGH
CVE-2026-78410 — util-linux Privilege Escalation via Race Condition in SUID Mount

A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized…

util-linux | Path Traversal
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
7.0 HIGH
CVE-2026-78409 — Linux Kernel Mount Subdirectory Symlink Traversal Vulnerability

The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate s…

util-linux | Path Traversal
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
7.9 HIGH
CVE-2026-78408 — util-linux nsenter Cgroup Privilege Escalation

The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel …

util-linux | Authorization
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.7 HIGH
CVE-2026-78222 — NGINX JavaScript Denial of Service Vulnerability

A vulnerability exists in NGINX JavaScript where a malformed HTTP response received by ngx.fetch() can crash an NGINX worker when trusted JavaScript reads Response.statusText. Exploitation requires c…

njs | Remote | Denial of Service
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.7 HIGH
CVE-2026-77180 — NGINX Ingress Controller Configuration Injection Vulnerability

When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields a…

nginx_ingress_controller | Remote | Injection
Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
8.8 HIGH
CVE-2026-66842 — F5 BIG-IP Traffic Management User Interface Privilege Escalation Vulnerability

BIG-IP has a vulnerability where an authenticated user of any role may be able to create administrative user accounts through an undisclosed request to Traffic Management User Interface (TMUI). I…

Sep 02, 2026 Sep 02, 2026
Sep 02, 2026
Sep 02, 2026
Showing 20 of 12567 Results