ZeroHour
Story · 1 source · 1 articlefirst updated ()

Jenkins 2026-09-02 security advisory affects core and 17 plugins; Canadian Cyber Centre relays as AV26-877 with core fixes 2.568.3 and 2.580

mediumAdvisoryimportance 25
What's new: Initial merged summary (no prior story): combined Jenkins' 2026-09-02 advisory with the Canadian Centre for Cyber Security relay AV26-877 (2026-09-03), adding the fixed Jenkins Core versions 2.568.3 and 2.580 and the Pipeline Build Step plugin named only in the Canadian relay.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Jenkins' September 2, 2026 advisory covers Jenkins Core, the update-center2 tool, and 17 plugins including GitLab, SAML, LDAP, and Microsoft Entra ID. Canada's Cyber Centre relayed it as AV26-877 on September 3, 2026, stating all Jenkins releases other than…

On September 2, 2026, Jenkins published a security advisory covering Jenkins Core, the update-center2 tool, and 17 plugins, including widely deployed ones such as GitLab, SAML, LDAP, Microsoft Entra ID, Script Security, SonarQube Scanner, and Pipeline: Groovy Libraries. The announcement text did not include CVE identifiers, affected version ranges, or any statement about active exploitation. On September 3, 2026, the Canadian Centre for Cyber Security relayed the advisory as AV26-877, adding version specifics absent from the announcement text: all Jenkins releases other than 2.568.3 and 2.580 are affected, meaning Jenkins Core is fixed in 2.568.3 and 2.580. The Canadian advisory describes the affected plugins as over a dozen, which is consistent with the 17 plugins in the Jenkins announcement, and it additionally names Pipeline Build Step; the two sources' plugin lists overlap on GitLab, SAML, LDAP, Microsoft Entra ID, and Script Security. Specific vulnerability types were not stated in either source; the Jenkins announcement notes only that its plugin advisories typically bundle fixes for issues such as stored XSS, CSRF, and missing permission checks. Administrators running any of the listed components should update them via the Jenkins update center and review the advisory for required updates.

  • Advisory date: September 2, 2026 (Jenkins security advisory).
  • Scope: Jenkins Core, the update-center2 tool, and 17 plugins per the Jenkins announcement; the Canadian relay (AV26-877) describes over a dozen plugins, consistent with 17.
  • Named plugins: GitLab, SAML, LDAP, Microsoft Entra ID, Script Security, SonarQube Scanner, and Pipeline: Groovy Libraries per the Jenkins announcement; the Canadian advisory (AV26-877) additionally names Pipeline Build Step.
  • Jenkins Core is fixed in 2.568.3 and 2.580; all other Jenkins releases are affected (per Canadian advisory AV26-877). The original announcement text did not include affected version ranges.
  • Canadian Centre for Cyber Security advisory ID: AV26-877, published 2026-09-03.
  • No CVE identifiers were provided in either source.
  • No active exploitation was reported in either source.
  • Specific vulnerability types were not stated; the Jenkins announcement characterizes its plugin advisories as typically covering stored XSS, CSRF, and missing permission checks.

Coverage timeline

  1. · 14d ago
    Jenkins Security Advisories· 25
    Jenkins Security Advisory 2026-09-02

    Jenkins releases a security advisory affecting Jenkins Core, update-center2, and 17 plugins including GitLab, SAML, LDAP, Microsoft Entra ID, and Script Security.