Jenkins
CD Foundation · current 2.579
The current version of Jenkins is 2.579 (as of 26/08/2026). patchletter checks the official source daily and emails you every new release.
Actively exploited vulnerabilities
The US cybersecurity agency CISA lists these vulnerabilities in its catalog of Known Exploited Vulnerabilities. Check your version and patch or mitigate promptly.
9.8 critical · over the network, without login · CISA deadline was 9 Sept 24
- CVE-2018-1000861Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability
9.8 critical · over the network, without login · CISA deadline was 10 Aug 22
- CVE-2017-1000353Jenkins Remote Code Execution Vulnerability
9.8 critical · over the network, without login · CISA deadline was 23 Oct 25
- CVE-2015-5317Jenkins User Interface (UI) Information Disclosure Vulnerability
7.5 high · over the network, without login · CISA deadline was 2 Jun 23
Source: CISA KEV. The CVE is matched to the product automatically — when in doubt, the linked NVD entry applies.
BSI security advisories
Advisories the German BSI (CERT-Bund) published for this product. Whether your version is affected is stated in the advisory itself.
- http/2 Implementierungen: Schwachstelle ermöglicht Denial of Service
WID-SEC-W-2023-2618 · 14 Aug
- Jenkins Plugins: Mehrere Schwachstellen
WID-SEC-W-2026-2665 · 6 Aug
- Jenkins Plugins: Mehrere Schwachstellen
WID-SEC-W-2026-2074 · 25 Jun
- Jenkins: Mehrere Schwachstellen
WID-SEC-W-2026-1884 · 16 Jun
- Jenkins Plugins: Mehrere Schwachstellen
WID-SEC-W-2026-1707 · 28 May
Jenkins at a glance
Jenkins is a widely used open-source automation server for CI/CD. Jenkins ships weekly and LTS releases plus frequent security advisories covering the core and its huge plugin ecosystem; as a build system with credentials and deploy reach, prompt patching is essential.
For admins the LTS line is the right base for production. The plugins are where most security issues live — keep them minimal, current, and from trusted sources, and read the security advisories that bundle plugin fixes. Jenkins holds credentials to many systems and executes pipeline code, so lock it down: authentication, least-privilege, isolated agents, and no anonymous access. Update through the built-in mechanism; back up the config (JENKINS_HOME) first. Subscribe to Jenkins security advisories; patchletter surfaces new releases.
Version history & changelog · as detected by patchletter
| Version | Channel | Date | Notes |
|---|---|---|---|
| 2.579 | STABLE | 26/08/2026 | Release notes → |
| 2.578 | STABLE | 19/08/2026 | Release notes → |
| 2.577 | STABLE | 12/08/2026 | Release notes → |
| 2.576 | STABLE | 06/08/2026 | Release notes → |
| 2.575 | STABLE | 29/07/2026 | Release notes → |
| 2.574 | STABLE | 22/07/2026 | Release notes → |
| 2.573 | STABLE | 15/07/2026 | Release notes → |
| 2.572 | STABLE | 08/07/2026 | Release notes → |
Frequently asked questions
- What is the latest version of Jenkins?
- Jenkins 2.579, released 26/08/2026. patchletter checks the vendor's official source daily for new releases.
- Where can I find the Jenkins release notes?
- The version history above links to the vendor's official release notes where the vendor publishes them. patchletter deliberately stores no vendor full texts.
- How do I get notified about new Jenkins updates?
- Free by email: patchletter reports every new release — instantly or bundled as a digest. Unsubscribe anytime with one click.
Never miss a Jenkins update
We check the source daily and email you — instantly or as a digest. Free, one-click unsubscribe.
Watch JenkinsEmbed this badge
Shows the current Jenkins version and updates itself. Free to use, no account needed.
[](https://patchletter.com/en/software/jenkins)https://patchletter.com/badge/jenkins.svgAlso available: ?v=eol (end of support) and ?v=cve (actively exploited).