ThreatCluster[verified]@threatclusterPatch
Jenkins Core is affected by a critical stored XSS vulnerability (CVE‑2026‑27099) that exposes build environments; admins are urged to plan and apply the necessary fixes.
ThreatSynop[verified]@ThreatSynopPatch
Jenkins disclosed two core vulnerabilities (stored XSS in CVE-2026-27099 and build info leak in CVE-2026-27100). Users are advised to upgrade to Jenkins 2.551 or LTS 2.541.2, or apply CSP mitigation, to patch the issues.
Open Source Security mailing list@oss_securityPatch
An advisory reports two Jenkins vulnerabilities – a stored XSS (CVE‑2026‑27099) and a run‑parameter info disclosure (CVE‑2026‑27100) – and notes that they are fixed in Jenkins 2.551 and 2.541.2.
CVE@CVEnewDisclosure
The CVE details a Jenkins vulnerability where users can reference builds they lack access to via Run Parameter values, potentially enabling unauthorized actions.
iototsecnews@iototsecnewsPatch
The article announces that Jenkins CVE‑2026‑27099 and CVE‑2026‑27100, involving XSS and information disclosure, have been patched, detailing the technical nature of the flaws.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The text announces CVE‑2026‑27100, an information‑disclosure flaw in Jenkins’ run‑parameter configuration, and provides a link to a vulnerability details page.
Autumn Good@autumn_good_35Disclosure
The text announces two new Jenkins CVEs—CVE-2026-27099 (stored XSS) and CVE-2026-27100 (build info disclosure)—providing severity scores and a link to the official advisory.