Vendor

Jenkins

As of , 6 Jenkins vulnerabilities are on CISA's list of exploited vulnerabilities, 1 of them used in ransomware campaigns; 0 were added in 2026. Patch first: CVE-2017-1000353.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2017-1000353Remote Code ExecutionJenkins JenkinsPatch this weekMetasploit module; EPSS 0.990.99
2CVE-2024-23897Path TraversalJenkins Jenkins Command Line Interface (CLI)Patch this weekRansomware use; Metasploit module; EPSS 0.990.99
3CVE-2019-1003029Sandbox BypassJenkins Script Security PluginPatch this weekMetasploit module; EPSS 0.740.74
4CVE-2018-1000861Deserialization of Untrusted DataJenkins Jenkins Stapler Web FrameworkPatch this weekMetasploit module; EPSS 0.980.98
5CVE-2019-1003030Remote Code ExecutionJenkins Matrix Project PluginPatch this weekEPSS 0.970.97
6CVE-2015-5317Information DisclosureJenkins Jenkins User Interface (UI)Patch soon0.23

Products

  • Jenkins1 entry
  • Jenkins Command Line Interface (CLI)1 entry
  • Jenkins Stapler Web Framework1 entry
  • Jenkins User Interface (UI)1 entry
  • Matrix Project Plugin1 entry
  • Script Security Plugin1 entry

Added each year

1232022: 3320222023: 1120232024: 1120242025: 1120252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20223
20231
20241
20251
2026none

Used in ransomware