CyberMax
Home › Exploited CVEs

Jenkins known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 6 Jenkins CVEs as exploited in the wild. 1 were added in the last 12 months (latest 2025-10-02), and 1 are known to be used in ransomware campaigns.

Jenkins CVEs added to CISA KEV per year
2022: 3202232023: 1202312024: 1202412025: 120251

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected Jenkins products

Jenkins (1), Jenkins Command Line Interface (CLI) (1), Jenkins User Interface (UI) (1), Script Security Plugin (1), Matrix Project Plugin (1), Jenkins Stapler Web Framework (1).

All Jenkins CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2017-1000353JenkinsRemote Code Execution2025-10-022025-10-2399.7%–
CVE-2024-23897Jenkins Command Line Interface (CLI)Command Line Interface (CLI) Path Traversal2024-08-192024-09-09100.0%Yes
CVE-2015-5317Jenkins User Interface (UI)User Interface (UI) Information Disclosure2023-05-122023-06-0223.0%–
CVE-2019-1003029Script Security PluginScript Security Plugin Sandbox Bypass2022-04-252022-05-1673.9%–
CVE-2019-1003030Matrix Project PluginMatrix Project Plugin Remote Code Execution2022-03-252022-04-1596.9%–
CVE-2018-1000861Jenkins Stapler Web FrameworkStapler Web Framework Deserialization of Untrusted Data2022-02-102022-08-1098.3%–
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors