Jenkins known exploited vulnerabilities
CISA lists 6 Jenkins CVEs as exploited in the wild. 1 were added in the last 12 months (latest 2025-10-02), and 1 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2024-23897 (Jenkins Command Line Interface (CLI)): EPSS 100.0%, added 2024-08-19
- CVE-2017-1000353 (Jenkins): EPSS 99.7%, added 2025-10-02
- CVE-2018-1000861 (Jenkins Stapler Web Framework): EPSS 98.3%, added 2022-02-10
- CVE-2019-1003030 (Matrix Project Plugin): EPSS 96.9%, added 2022-03-25
- CVE-2019-1003029 (Script Security Plugin): EPSS 73.9%, added 2022-04-25
Most affected Jenkins products
Jenkins (1), Jenkins Command Line Interface (CLI) (1), Jenkins User Interface (UI) (1), Script Security Plugin (1), Matrix Project Plugin (1), Jenkins Stapler Web Framework (1).
All Jenkins CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2017-1000353 | Jenkins | Remote Code Execution | 2025-10-02 | 2025-10-23 | 99.7% | – |
| CVE-2024-23897 | Jenkins Command Line Interface (CLI) | Command Line Interface (CLI) Path Traversal | 2024-08-19 | 2024-09-09 | 100.0% | Yes |
| CVE-2015-5317 | Jenkins User Interface (UI) | User Interface (UI) Information Disclosure | 2023-05-12 | 2023-06-02 | 23.0% | – |
| CVE-2019-1003029 | Script Security Plugin | Script Security Plugin Sandbox Bypass | 2022-04-25 | 2022-05-16 | 73.9% | – |
| CVE-2019-1003030 | Matrix Project Plugin | Matrix Project Plugin Remote Code Execution | 2022-03-25 | 2022-04-15 | 96.9% | – |
| CVE-2018-1000861 | Jenkins Stapler Web Framework | Stapler Web Framework Deserialization of Untrusted Data | 2022-02-10 | 2022-08-10 | 98.3% | – |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors