Skip to content

Warning: High Arbitrary Code Execution Vulnerability in Jenkins, Patch Immediately!

Ccb.Belgium.Be June 17, 2026

CVE-2026-53435 is deserialization vulnerability in Jenkins, which is a widely used open-source automation server. This vulnerability allows an authenticated user to impersonate any other user and perform actions on their behalf which includes arbitrary code execution and reading files.

Jenkins is mostly used in the center of organizations which makes it particularly interesting for attackers to target. Successful exploitation leads to a high impact on the confidentiality, integrity and availability of the affected system.

It is possible for an attacker to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an config.xml submission, which allows them to handle HTTP requests afterwards.

Attackers need to have at least certain permissions to exploit this vulnerability. When exploited attackers can impersonate any user and send HTTP requests on their behalf, which also includes running arbitrary code using the script console.

Patch The Centre for Cybersecurity Belgium strongly recommends installing updates for vulnerable devices with the highest priority after thorough testing.

Monitor/Detect The CCB recommends organizations upscale monitoring and detection capabilities to identify any related suspicious activity, ensuring a swift response in case of an intrusion.

In case of an intrusion, you can report an incident via .

While patching appliances or software to the newest version may provide safety from future exploitation, it does not remediate historic compromise.

NIST NVD -