CVE-2026-84645: Jenkins
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, objects of types marked as storing their configuration in independent top-level configuration files in Jenkins (such as the global configuration and jobs) can appear as nested field values in user-submitted `config.xml` documents and subsequently handle HTTP requests via Stapler, resulting in remote code execution.
Affected products
- Jenkins Jenkins: before 2.568.3 (fixed in 2.568.3); before 2.580 (fixed in 2.580)
Published 2026-09-02. Last modified 2026-09-11.