E-tomatot[verified]@ETomatot24044General
The post identifies general setup shortcomings (anonymous user permissions and HTTP use) that could allow exploitation of CVE‑2026‑33002, but it provides no technical details, PoC, or patch information.
Gray Hats@the_yellow_fallPatch
Jenkins has released patches for CVE‑2026‑33001 and CVE‑2026‑33002, which allowed remote code execution and full pipeline compromise; users are advised to upgrade to version 2.555.
Andre Gironda@AndreGirondaDisclosure
The advisory discloses CVE-2026-33001 and CVE-2026-33002, indicating that Jenkins versions before 2.555 and LTS 2.541.3 fail to safely process symbolic links in tar/tgz archives, enabling arbitrary file writes and potential code execution.
Autumn Good@autumn_good_35Disclosure
The text announces a Jenkins security advisory for CVE‑2026‑33001 through CVE‑2026‑33004, highlighting potential code execution via archive extraction on controllers.
iototsecnews@iototsecnewsDisclosure
The article announces several newly identified Jenkins core and plugin vulnerabilities, detailing how they can lead to remote code execution and authentication bypass, without mention of PoC, exploit code, or patches.
PulsePatch.io@pulsepatchioDisclosure
The post announces a DNS rebinding vulnerability (CVE-2026-33002) affecting Jenkins WebSocket CLI origin validation, noting it can bypass security controls and urging users to assess their deployments.
CERT-PY@CERTpyDisclosure
The tweet announces two new Jenkins CVEs (2026-33002 & 2026-33001) and points to a website for additional information, without sharing exploitation or mitigation details.
CVE@CVEnewDisclosure
The statement announces CVE-2026-33002, listing affected Jenkins versions and describing an origin validation flaw in the CLI WebSocket, with no mention of PoC, exploit, or mitigation.