Skip to content
Critical Jenkins Vulnerability Exposes Build Environments to XSS Attacks

Critical Jenkins Vulnerability Exposes Build Environments to XSS Attacks

First seen 20 Feb 2026, 15:17 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

A critical stored Cross-Site Scripting (XSS) vulnerability has been identified in Jenkins Core, affecting build environments. The vulnerabilities, tracked as CVE-2026-27099 and CVE-2026-27100, were disclosed by the European Commission under the Jenkins Bug Bounty Program. CVE-2026-27099 is classified as high-severity and poses significant security risks to users.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 210d ago How this analysis works

Timeline

2026-02-18
CVE-2026-27099 published
2026-02-18
CVE-2026-27100 published
2026-02-20
Articles published detailing the vulnerabilities

More articles in this cluster (2)

Following this threat?

Track European Commission and CVE-2026-27099 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed