Critical Jenkins Vulnerability Exposes Build Environments to XSS Attacks
Article Content
Browse articles
A critical stored Cross-Site Scripting (XSS) vulnerability has been identified in Jenkins Core, affecting build environments. The vulnerabilities, tracked as CVE-2026-27099 and CVE-2026-27100, were disclosed by the European Commission under the Jenkins Bug Bounty Program. CVE-2026-27099 is classified as high-severity and poses significant security risks to users.
Ask AI about this cluster
Answers cite the sources they use
Updated 210d ago How this analysis works
Timeline
2026-02-18
CVE-2026-27099 published
2026-02-18
CVE-2026-27100 published
2026-02-20
Articles published detailing the vulnerabilities
More articles in this cluster (2)
Following this threat?
Track European Commission and CVE-2026-27099 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Twitch Chat Messages Exploit OBS Studio via Chromium Vulnerability A vulnerability in OBS Studio allows malicious Twitch chat messages to execute native code on streamers' Windows PCs. This exploit targets users running OBS Studio version 32.2.2 or older, leveraging a cross-site scripting (XSS) flaw in custom overlays that render viewer messages as unsanitized HTML. The attack…