Merge News[verified]@mergenewsappPatch
The post highlights a critical Jenkins vulnerability (CVE-2026-19429) that permits arbitrary file creation via TAR archives and urges users to apply a patch or update to protect their CI/CD pipelines.
Upwind Security MDR[verified]@UpwindMDRDisclosure
A new Jenkins RCE via symlink bypass (CVE‑2026‑19429) is disclosed with technical details, noting no patch yet, but no PoC or live exploitation evidence.
Infoflowcloud@infoflowcloudDisclosure
The tweet announces CVE-2026-19429, describing how Jenkins’ `FilePath.untarFrom()` improperly validates symlink destinations, allowing users with Item/Build access to exploit the flaw. No PoC, exploit code, patch, or evidence of live exploitation is provided.
CVE@CVEnewDisclosure
The post announces a Jenkins vulnerability where symlink targets are not validated, enabling users with Item/Build rights to exploit it, and links to the CVE record for more details.