WID-SEC-W-2026-2074
Vulnerability from csaf_certbund - Published: 2026-06-24 22:00 - Updated: 2026-08-26 22:00Summary
Jenkins Plugins: Mehrere Schwachstellen
Severity
Hoch
Notes
Das BSI ist als Anbieter für die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch dafür verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgfältig im Einzelfall zu prüfen.
Produktbeschreibung: Jenkins ist ein erweiterbarer, webbasierter Integration Server zur kontinuierlichen Unterstützung bei Softwareentwicklungen aller Art.
Angriff: Ein Angreifer kann mehrere Schwachstellen in Jenkins Plugins ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen und vertrauliche Informationen zu manipulieren oder offenzulegen.
Betroffene Betriebssysteme: - Sonstiges
- UNIX
- Windows
Affected products
Known affected
15 products
| Product | Identifier | Version | Remediation |
|---|---|---|---|
|
Jenkins Jenkins Gitee Plugin <1292.v2559f2f3f2c0
Jenkins / Jenkins
|
Gitee Plugin <1292.v2559f2f3f2c0 | ||
|
Jenkins Jenkins Git Parameter Plugin <462.463.v496a_59f698e5
Jenkins / Jenkins
|
Git Parameter Plugin <462.463.v496a_59f698e5 | ||
|
Jenkins Jenkins Git client Plugin <6.6.1
Jenkins / Jenkins
|
Git client Plugin <6.6.1 | ||
|
Jenkins Jenkins External Workspace Manager Plugin <1.4.0
Jenkins / Jenkins
|
External Workspace Manager Plugin <1.4.0 | ||
|
Jenkins Jenkins EC2 Fleet Plugin <4.2.3.540.va_6eedb_7b_c112
Jenkins / Jenkins
|
EC2 Fleet Plugin <4.2.3.540.va_6eedb_7b_c112 | ||
|
Jenkins Jenkins Script Security Plugin <1402.1405.vc96e74964250
Jenkins / Jenkins
|
Script Security Plugin <1402.1405.vc96e74964250 | ||
|
Red Hat OpenShift Developer Tools
Red Hat / OpenShift
|
cpe:/a:redhat:openshift:developer_tools
|
Developer Tools | |
|
Jenkins Jenkins Contrast Continuous Application Security Plugin <3.12
Jenkins / Jenkins
|
Contrast Continuous Application Security Plugin <3.12 | ||
|
Jenkins Jenkins Bitbucket Push and Pull Request Plugin <3.3.9
Jenkins / Jenkins
|
Bitbucket Push and Pull Request Plugin <3.3.9 | ||
|
Jenkins Jenkins Priority Sorter Plugin <936.937.v5581d0b_2ccb_a_
Jenkins / Jenkins
|
Priority Sorter Plugin <936.937.v5581d0b_2ccb_a_ | ||
|
Jenkins Jenkins Active Directory Plugin <2.41.2
Jenkins / Jenkins
|
Active Directory Plugin <2.41.2 | ||
|
Jenkins Jenkins Pipeline: Groovy Plugin <4331.4333.v50a_b_076c5199
Jenkins / Jenkins
|
Pipeline: Groovy Plugin <4331.4333.v50a_b_076c5199 | ||
|
Jenkins Jenkins MCP Server Plugin <0.178.vffe5a_e770f3b_
Jenkins / Jenkins
|
MCP Server Plugin <0.178.vffe5a_e770f3b_ | ||
|
Jenkins Jenkins Job Configuration History Plugin <1367.vc8fa_b_15101dc
Jenkins / Jenkins
|
Job Configuration History Plugin <1367.vc8fa_b_15101dc | ||
|
Jenkins Jenkins GitHub Branch Source Plugin <1967.1970.vd86979736546
Jenkins / Jenkins
|
GitHub Branch Source Plugin <1967.1970.vd86979736546 |
Affected products
Known affected
15 products, the same list as for
CVE-2026-57280
Affected products
Known affected
15 products, the same list as for
CVE-2026-57280
Affected products
Known affected
15 products, the same list as for
CVE-2026-57280
Affected products
Known affected
15 products, the same list as for
CVE-2026-57280
Affected products
Known affected
15 products, the same list as for
CVE-2026-57280
Affected products
Known affected
15 products, the same list as for
CVE-2026-57280
Affected products
Known affected
15 products, the same list as for
CVE-2026-57280
Affected products
Known affected
15 products, the same list as for
CVE-2026-57280
Affected products
Known affected
15 products, the same list as for
CVE-2026-57280
Affected products
Known affected
15 products, the same list as for
CVE-2026-57280
Affected products
Known affected
15 products, the same list as for
CVE-2026-57280
Affected products
Known affected
15 products, the same list as for
CVE-2026-57280
Affected products
Known affected
15 products, the same list as for
CVE-2026-57280
Affected products
Known affected
15 products, the same list as for
CVE-2026-57280
Affected products
Known affected
15 products, the same list as for
CVE-2026-57280
Affected products
Known affected
15 products, the same list as for
CVE-2026-57280
Affected products
Known affected
15 products, the same list as for
CVE-2026-57280
Affected products
Known affected
15 products, the same list as for
CVE-2026-57280
Affected products
Known affected
15 products, the same list as for
CVE-2026-57280
Affected products
Known affected
15 products, the same list as for
CVE-2026-57280
Affected products
Known affected
5 products
| Product | Identifier | Version | Remediation |
|---|---|---|---|
|
Jenkins Jenkins Zowe zDevOps Plugin
Jenkins / Jenkins
|
cpe:/a:cloudbees:jenkins:zowe_zdevops_plugin
|
Zowe zDevOps Plugin | |
|
Jenkins Jenkins OWASP ZAP Plugin
Jenkins / Jenkins
|
cpe:/a:cloudbees:jenkins:owasp_zap_plugin
|
OWASP ZAP Plugin | |
|
Jenkins Jenkins FitNesse Plugin
Jenkins / Jenkins
|
cpe:/a:cloudbees:jenkins:fitnesse_plugin
|
FitNesse Plugin | |
|
Jenkins Jenkins Assembla Plugin
Jenkins / Jenkins
|
cpe:/a:cloudbees:jenkins:assembla_plugin
|
Assembla Plugin | |
|
Red Hat OpenShift Developer Tools
Red Hat / OpenShift
|
cpe:/a:redhat:openshift:developer_tools
|
Developer Tools |
Affected products
Known affected
5 products, the same list as for
CVE-2026-57301
Affected products
Known affected
5 products, the same list as for
CVE-2026-57301
Affected products
Known affected
5 products, the same list as for
CVE-2026-57301
Affected products
Known affected
5 products, the same list as for
CVE-2026-57301
Affected products
Known affected
5 products, the same list as for
CVE-2026-57301
Affected products
Known affected
5 products, the same list as for
CVE-2026-57301
References
14 references
{
"document": {
"aggregate_severity": {
"text": "hoch"
},
"category": "csaf_base",
"csaf_version": "2.0",
"distribution": {
"tlp": {
"label": "WHITE",
"url": "https://www.first.org/tlp/"
}
},
"lang": "de-DE",
"notes": [
{
"category": "legal_disclaimer",
"text": "Das BSI ist als Anbieter f\u00fcr die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch daf\u00fcr verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgf\u00e4ltig im Einzelfall zu pr\u00fcfen."
},
{
"category": "description",
"text": "Jenkins ist ein erweiterbarer, webbasierter Integration Server zur kontinuierlichen Unterst\u00fctzung bei Softwareentwicklungen aller Art.",
"title": "Produktbeschreibung"
},
{
"category": "summary",
"text": "Ein Angreifer kann mehrere Schwachstellen in Jenkins Plugins ausnutzen, um beliebigen Programmcode auszuf\u00fchren, Sicherheitsma\u00dfnahmen zu umgehen und vertrauliche Informationen zu manipulieren oder offenzulegen.",
"title": "Angriff"
},
{
"category": "general",
"text": "- Sonstiges\n- UNIX\n- Windows",
"title": "Betroffene Betriebssysteme"
}
],
"publisher": {
"category": "other",
"contact_details": "csaf-provider@cert-bund.de",
"name": "Bundesamt f\u00fcr Sicherheit in der Informationstechnik",
"namespace": "https://www.bsi.bund.de"
},
"references": [
{
"category": "self",
"summary": "WID-SEC-W-2026-2074 - CSAF Version",
"url": "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2074.json"
},
{
"category": "self",
"summary": "WID-SEC-2026-2074 - Portal Version",
"url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2074"
},
{
"category": "external",
"summary": "Jenkins Security Advisory 2026-06-24 vom 2026-06-24",
"url": "https://www.jenkins.io/security/advisory/2026-06-24/"
},
{
"category": "external",
"summary": "Red Hat Security Advisory RHSA-2026:60251 vom 2026-08-26",
"url": "https://access.redhat.com/errata/RHSA-2026:60251"
},
{
"category": "external",
"summary": "Red Hat Security Advisory RHSA-2026:60254 vom 2026-08-26",
"url": "https://access.redhat.com/errata/RHSA-2026:60254"
},
{
"category": "external",
"summary": "Red Hat Security Advisory RHSA-2026:60246 vom 2026-08-26",
"url": "https://access.redhat.com/errata/RHSA-2026:60246"
},
{
"category": "external",
"summary": "Red Hat Security Advisory RHSA-2026:60256 vom 2026-08-26",
"url": "https://access.redhat.com/errata/RHSA-2026:60256"
},
{
"category": "external",
"summary": "Red Hat Security Advisory RHSA-2026:60247 vom 2026-08-26",
"url": "https://access.redhat.com/errata/RHSA-2026:60247"
},
{
"category": "external",
"summary": "Red Hat Security Advisory RHSA-2026:60248 vom 2026-08-26",
"url": "https://access.redhat.com/errata/RHSA-2026:60248"
},
{
"category": "external",
"summary": "Red Hat Security Advisory RHSA-2026:60249 vom 2026-08-26",
"url": "https://access.redhat.com/errata/RHSA-2026:60249"
},
{
"category": "external",
"summary": "Red Hat Security Advisory RHSA-2026:60250 vom 2026-08-26",
"url": "https://access.redhat.com/errata/RHSA-2026:60250"
},
{
"category": "external",
"summary": "Red Hat Security Advisory RHSA-2026:60252 vom 2026-08-26",
"url": "https://access.redhat.com/errata/RHSA-2026:60252"
},
{
"category": "external",
"summary": "Red Hat Security Advisory RHSA-2026:60239 vom 2026-08-26",
"url": "https://access.redhat.com/errata/RHSA-2026:60239"
},
{
"category": "external",
"summary": "Red Hat Security Advisory RHSA-2026:60259 vom 2026-08-26",
"url": "https://access.redhat.com/errata/RHSA-2026:60259"
}
],
"source_lang": "en-US",
"title": "Jenkins Plugins: Mehrere Schwachstellen",
"tracking": {
"current_release_date": "2026-08-26T22:00:00.000+00:00",
"generator": {
"date": "2026-08-27T08:59:53.156+00:00",
"engine": {
"name": "BSI-WID",
"version": "1.6.0"
}
},
"id": "WID-SEC-W-2026-2074",
"initial_release_date": "2026-06-24T22:00:00.000+00:00",
"revision_history": [
{
"date": "2026-06-24T22:00:00.000+00:00",
"number": "1",
"summary": "Initiale Fassung"
},
{
"date": "2026-08-25T22:00:00.000+00:00",
"number": "2",
"summary": "Neue Updates von Red Hat aufgenommen"
},
{
"date": "2026-08-26T22:00:00.000+00:00",
"number": "3",
"summary": "Neue Updates von Red Hat aufgenommen"
}
],
"status": "final",
"version": "3"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_version_range",
"name": "Active Directory Plugin \u003c2.41.2",
"product": {
"name": "Jenkins Jenkins Active Directory Plugin \u003c2.41.2",
"product_id": "T055777"
}
},
{
"category": "product_version",
"name": "Active Directory Plugin 2.41.2",
"product": {
"name": "Jenkins Jenkins Active Directory Plugin 2.41.2",
"product_id": "T055777-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:cloudbees:jenkins:active_directory_plugin__2.41.2"
}
}
},
{
"category": "product_version_range",
"name": "Bitbucket Push and Pull Request Plugin \u003c3.3.9",
"product": {
"name": "Jenkins Jenkins Bitbucket Push and Pull Request Plugin \u003c3.3.9",
"product_id": "T055778"
}
},
{
"category": "product_version",
"name": "Bitbucket Push and Pull Request Plugin 3.3.9",
"product": {
"name": "Jenkins Jenkins Bitbucket Push and Pull Request Plugin 3.3.9",
"product_id": "T055778-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:cloudbees:jenkins:bitbucket_push_and_pull_request_plugin__3.3.9"
}
}
},
{
"category": "product_version_range",
"name": "Contrast Continuous Application Security Plugin \u003c3.12",
"product": {
"name": "Jenkins Jenkins Contrast Continuous Application Security Plugin \u003c3.12",
"product_id": "T055779"
}
},
{
"category": "product_version",
"name": "Contrast Continuous Application Security Plugin 3.12",
"product": {
"name": "Jenkins Jenkins Contrast Continuous Application Security Plugin 3.12",
"product_id": "T055779-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:cloudbees:jenkins:contrast_continuous_application_security_plugin__3.12"
}
}
},
{
"category": "product_version_range",
"name": "EC2 Fleet Plugin \u003c4.2.3.540.va_6eedb_7b_c112",
"product": {
"name": "Jenkins Jenkins EC2 Fleet Plugin \u003c4.2.3.540.va_6eedb_7b_c112",
"product_id": "T055780"
}
},
{
"category": "product_version",
"name": "EC2 Fleet Plugin 4.2.3.540.va_6eedb_7b_c112",
"product": {
"name": "Jenkins Jenkins EC2 Fleet Plugin 4.2.3.540.va_6eedb_7b_c112",
"product_id": "T055780-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:cloudbees:jenkins:ec2_fleet_plugin__4.2.3.540.va_6eedb_7b_c112"
}
}
},
{
"category": "product_version_range",
"name": "External Workspace Manager Plugin \u003c1.4.0",
"product": {
"name": "Jenkins Jenkins External Workspace Manager Plugin \u003c1.4.0",
"product_id": "T055781"
}
},
{
"category": "product_version",
"name": "External Workspace Manager Plugin 1.4.0",
"product": {
"name": "Jenkins Jenkins External Workspace Manager Plugin 1.4.0",
"product_id": "T055781-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:cloudbees:jenkins:external_workspace_manager_plugin__1.4.0"
}
}
},
{
"category": "product_version_range",
"name": "Git client Plugin \u003c6.6.1",
"product": {
"name": "Jenkins Jenkins Git client Plugin \u003c6.6.1",
"product_id": "T055782"
}
},
{
"category": "product_version",
"name": "Git client Plugin 6.6.1",
"product": {
"name": "Jenkins Jenkins Git client Plugin 6.6.1",
"product_id": "T055782-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:cloudbees:jenkins:git_client_plugin__6.6.1"
}
}
},
{
"category": "product_version_range",
"name": "Git Parameter Plugin \u003c462.463.v496a_59f698e5",
"product": {
"name": "Jenkins Jenkins Git Parameter Plugin \u003c462.463.v496a_59f698e5",
"product_id": "T055783"
}
},
{
"category": "product_version",
"name": "Git Parameter Plugin 462.463.v496a_59f698e5",
"product": {
"name": "Jenkins Jenkins Git Parameter Plugin 462.463.v496a_59f698e5",
"product_id": "T055783-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:cloudbees:jenkins:git_parameter_plugin__462.463.v496a_59f698e5"
}
}
},
{
"category": "product_version_range",
"name": "Gitee Plugin \u003c1292.v2559f2f3f2c0",
"product": {
"name": "Jenkins Jenkins Gitee Plugin \u003c1292.v2559f2f3f2c0",
"product_id": "T055784"
}
},
{
"category": "product_version",
"name": "Gitee Plugin 1292.v2559f2f3f2c0",
"product": {
"name": "Jenkins Jenkins Gitee Plugin 1292.v2559f2f3f2c0",
"product_id": "T055784-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:cloudbees:jenkins:gitee_plugin___1292.v2559f2f3f2c0"
}
}
},
{
"category": "product_version_range",
"name": "GitHub Branch Source Plugin \u003c1967.1970.vd86979736546",
"product": {
"name": "Jenkins Jenkins GitHub Branch Source Plugin \u003c1967.1970.vd86979736546",
"product_id": "T055785"
}
},
{
"category": "product_version",
"name": "GitHub Branch Source Plugin 1967.1970.vd86979736546",
"product": {
"name": "Jenkins Jenkins GitHub Branch Source Plugin 1967.1970.vd86979736546",
"product_id": "T055785-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:cloudbees:jenkins:github_branch_source_plugin__1967.1970.vd86979736546"
}
}
},
{
"category": "product_version_range",
"name": "Job Configuration History Plugin \u003c1367.vc8fa_b_15101dc",
"product": {
"name": "Jenkins Jenkins Job Configuration History Plugin \u003c1367.vc8fa_b_15101dc",
"product_id": "T055786"
}
},
{
"category": "product_version",
"name": "Job Configuration History Plugin 1367.vc8fa_b_15101dc",
"product": {
"name": "Jenkins Jenkins Job Configuration History Plugin 1367.vc8fa_b_15101dc",
"product_id": "T055786-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:cloudbees:jenkins:job_configuration_history_plugin__1367.vc8fa_b_15101dc"
}
}
},
{
"category": "product_version_range",
"name": "MCP Server Plugin \u003c0.178.vffe5a_e770f3b_",
"product": {
"name": "Jenkins Jenkins MCP Server Plugin \u003c0.178.vffe5a_e770f3b_",
"product_id": "T055787"
}
},
{
"category": "product_version",
"name": "MCP Server Plugin 0.178.vffe5a_e770f3b_",
"product": {
"name": "Jenkins Jenkins MCP Server Plugin 0.178.vffe5a_e770f3b_",
"product_id": "T055787-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:cloudbees:jenkins:mcp_server_plugin__0.178.vffe5a_e770f3b_"
}
}
},
{
"category": "product_version_range",
"name": "Pipeline: Groovy Plugin \u003c4331.4333.v50a_b_076c5199",
"product": {
"name": "Jenkins Jenkins Pipeline: Groovy Plugin \u003c4331.4333.v50a_b_076c5199",
"product_id": "T055788"
}
},
{
"category": "product_version",
"name": "Pipeline: Groovy Plugin 4331.4333.v50a_b_076c5199",
"product": {
"name": "Jenkins Jenkins Pipeline: Groovy Plugin 4331.4333.v50a_b_076c5199",
"product_id": "T055788-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:cloudbees:jenkins:pipeline_groovy_plugin__4331.4333.v50a_b_076c5199"
}
}
},
{
"category": "product_version_range",
"name": "Priority Sorter Plugin \u003c936.937.v5581d0b_2ccb_a_",
"product": {
"name": "Jenkins Jenkins Priority Sorter Plugin \u003c936.937.v5581d0b_2ccb_a_",
"product_id": "T055789"
}
},
{
"category": "product_version_range",
"name": "Priority Sorter Plugin 936.937.v5581d0b_2ccb_a_",
"product": {
"name": "Jenkins Jenkins Priority Sorter Plugin 936.937.v5581d0b_2ccb_a_",
"product_id": "T055789-fixed"
}
},
{
"category": "product_version_range",
"name": "Script Security Plugin \u003c1402.1405.vc96e74964250",
"product": {
"name": "Jenkins Jenkins Script Security Plugin \u003c1402.1405.vc96e74964250",
"product_id": "T055790"
}
},
{
"category": "product_version",
"name": "Script Security Plugin 1402.1405.vc96e74964250",
"product": {
"name": "Jenkins Jenkins Script Security Plugin 1402.1405.vc96e74964250",
"product_id": "T055790-fixed",
"product_identification_helper": {
"cpe": "cpe:/a:cloudbees:jenkins:script_security_plugin__1402.1405.vc96e74964250"
}
}
},
{
"category": "product_version",
"name": "Assembla Plugin",
"product": {
"name": "Jenkins Jenkins Assembla Plugin",
"product_id": "T055791",
"product_identification_helper": {
"cpe": "cpe:/a:cloudbees:jenkins:assembla_plugin"
}
}
},
{
"category": "product_version",
"name": "FitNesse Plugin",
"product": {
"name": "Jenkins Jenkins FitNesse Plugin",
"product_id": "T055792",
"product_identification_helper": {
"cpe": "cpe:/a:cloudbees:jenkins:fitnesse_plugin"
}
}
},
{
"category": "product_version",
"name": "OWASP ZAP Plugin",
"product": {
"name": "Jenkins Jenkins OWASP ZAP Plugin",
"product_id": "T055793",
"product_identification_helper": {
"cpe": "cpe:/a:cloudbees:jenkins:owasp_zap_plugin"
}
}
},
{
"category": "product_version",
"name": "Zowe zDevOps Plugin",
"product": {
"name": "Jenkins Jenkins Zowe zDevOps Plugin",
"product_id": "T055794",
"product_identification_helper": {
"cpe": "cpe:/a:cloudbees:jenkins:zowe_zdevops_plugin"
}
}
}
],
"category": "product_name",
"name": "Jenkins"
}
],
"category": "vendor",
"name": "Jenkins"
},
{
"branches": [
{
"branches": [
{
"category": "product_version",
"name": "Developer Tools",
"product": {
"name": "Red Hat OpenShift Developer Tools",
"product_id": "T058670",
"product_identification_helper": {
"cpe": "cpe:/a:redhat:openshift:developer_tools"
}
}
}
],
"category": "product_name",
"name": "OpenShift"
}
],
"category": "vendor",
"name": "Red Hat"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2026-57280",
"product_status": {
"known_affected": [
"T055784",
"T055783",
"T055782",
"T055781",
"T055780",
"T055790",
"T058670",
"T055779",
"T055778",
"T055789",
"T055777",
"T055788",
"T055787",
"T055786",
"T055785"
]
},
"release_date": "2026-06-24T22:00:00.000+00:00",
"title": "CVE-2026-57280"
},
{
"cve": "CVE-2026-57281",
"product_status": {
"known_affected": [
"T055784",
"T055783",
"T055782",
"T055781",
"T055780",
"T055790",
"T058670",
"T055779",
"T055778",
"T055789",
"T055777",
"T055788",
"T055787",
"T055786",
"T055785"
]
},
"release_date": "2026-06-24T22:00:00.000+00:00",
"title": "CVE-2026-57281"
},
{
"cve": "CVE-2026-57282",
"product_status": {
"known_affected": [
"T055784",
"T055783",
"T055782",
"T055781",
"T055780",
"T055790",
"T058670",
"T055779",
"T055778",
"T055789",
"T055777",
"T055788",
"T055787",
"T055786",
"T055785"
]
},
"release_date": "2026-06-24T22:00:00.000+00:00",
"title": "CVE-2026-57282"
},
{
"cve": "CVE-2026-57283",
"product_status": {
"known_affected": [
"T055784",
"T055783",
"T055782",
"T055781",
"T055780",
"T055790",
"T058670",
"T055779",
"T055778",
"T055789",
"T055777",
"T055788",
"T055787",
"T055786",
"T055785"
]
},
"release_date": "2026-06-24T22:00:00.000+00:00",
"title": "CVE-2026-57283"
},
{
"cve": "CVE-2026-57284",
"product_status": {
"known_affected": [
"T055784",
"T055783",
"T055782",
"T055781",
"T055780",
"T055790",
"T058670",
"T055779",
"T055778",
"T055789",
"T055777",
"T055788",
"T055787",
"T055786",
"T055785"
]
},
"release_date": "2026-06-24T22:00:00.000+00:00",
"title": "CVE-2026-57284"
},
{
"cve": "CVE-2026-57285",
"product_status": {
"known_affected": [
"T055784",
"T055783",
"T055782",
"T055781",
"T055780",
"T055790",
"T058670",
"T055779",
"T055778",
"T055789",
"T055777",
"T055788",
"T055787",
"T055786",
"T055785"
]
},
"release_date": "2026-06-24T22:00:00.000+00:00",
"title": "CVE-2026-57285"
},
{
"cve": "CVE-2026-57286",
"product_status": {
"known_affected": [
"T055784",
"T055783",
"T055782",
"T055781",
"T055780",
"T055790",
"T058670",
"T055779",
"T055778",
"T055789",
"T055777",
"T055788",
"T055787",
"T055786",
"T055785"
]
},
"release_date": "2026-06-24T22:00:00.000+00:00",
"title": "CVE-2026-57286"
},
{
"cve": "CVE-2026-57287",
"product_status": {
"known_affected": [
"T055784",
"T055783",
"T055782",
"T055781",
"T055780",
"T055790",
"T058670",
"T055779",
"T055778",
"T055789",
"T055777",
"T055788",
"T055787",
"T055786",
"T055785"
]
},
"release_date": "2026-06-24T22:00:00.000+00:00",
"title": "CVE-2026-57287"
},
{
"cve": "CVE-2026-57288",
"product_status": {
"known_affected": [
"T055784",
"T055783",
"T055782",
"T055781",
"T055780",
"T055790",
"T058670",
"T055779",
"T055778",
"T055789",
"T055777",
"T055788",
"T055787",
"T055786",
"T055785"
]
},
"release_date": "2026-06-24T22:00:00.000+00:00",
"title": "CVE-2026-57288"
},
{
"cve": "CVE-2026-57289",
"product_status": {
"known_affected": [
"T055784",
"T055783",
"T055782",
"T055781",
"T055780",
"T055790",
"T058670",
"T055779",
"T055778",
"T055789",
"T055777",
"T055788",
"T055787",
"T055786",
"T055785"
]
},
"release_date": "2026-06-24T22:00:00.000+00:00",
"title": "CVE-2026-57289"
},
{
"cve": "CVE-2026-57290",
"product_status": {
"known_affected": [
"T055784",
"T055783",
"T055782",
"T055781",
"T055780",
"T055790",
"T058670",
"T055779",
"T055778",
"T055789",
"T055777",
"T055788",
"T055787",
"T055786",
"T055785"
]
},
"release_date": "2026-06-24T22:00:00.000+00:00",
"title": "CVE-2026-57290"
},
{
"cve": "CVE-2026-57291",
"product_status": {
"known_affected": [
"T055784",
"T055783",
"T055782",
"T055781",
"T055780",
"T055790",
"T058670",
"T055779",
"T055778",
"T055789",
"T055777",
"T055788",
"T055787",
"T055786",
"T055785"
]
},
"release_date": "2026-06-24T22:00:00.000+00:00",
"title": "CVE-2026-57291"
},
{
"cve": "CVE-2026-57292",
"product_status": {
"known_affected": [
"T055784",
"T055783",
"T055782",
"T055781",
"T055780",
"T055790",
"T058670",
"T055779",
"T055778",
"T055789",
"T055777",
"T055788",
"T055787",
"T055786",
"T055785"
]
},
"release_date": "2026-06-24T22:00:00.000+00:00",
"title": "CVE-2026-57292"
},
{
"cve": "CVE-2026-57293",
"product_status": {
"known_affected": [
"T055784",
"T055783",
"T055782",
"T055781",
"T055780",
"T055790",
"T058670",
"T055779",
"T055778",
"T055789",
"T055777",
"T055788",
"T055787",
"T055786",
"T055785"
]
},
"release_date": "2026-06-24T22:00:00.000+00:00",
"title": "CVE-2026-57293"
},
{
"cve": "CVE-2026-57294",
"product_status": {
"known_affected": [
"T055784",
"T055783",
"T055782",
"T055781",
"T055780",
"T055790",
"T058670",
"T055779",
"T055778",
"T055789",
"T055777",
"T055788",
"T055787",
"T055786",
"T055785"
]
},
"release_date": "2026-06-24T22:00:00.000+00:00",
"title": "CVE-2026-57294"
},
{
"cve": "CVE-2026-57295",
"product_status": {
"known_affected": [
"T055784",
"T055783",
"T055782",
"T055781",
"T055780",
"T055790",
"T058670",
"T055779",
"T055778",
"T055789",
"T055777",
"T055788",
"T055787",
"T055786",
"T055785"
]
},
"release_date": "2026-06-24T22:00:00.000+00:00",
"title": "CVE-2026-57295"
},
{
"cve": "CVE-2026-57296",
"product_status": {
"known_affected": [
"T055784",
"T055783",
"T055782",
"T055781",
"T055780",
"T055790",
"T058670",
"T055779",
"T055778",
"T055789",
"T055777",
"T055788",
"T055787",
"T055786",
"T055785"
]
},
"release_date": "2026-06-24T22:00:00.000+00:00",
"title": "CVE-2026-57296"
},
{
"cve": "CVE-2026-57297",
"product_status": {
"known_affected": [
"T055784",
"T055783",
"T055782",
"T055781",
"T055780",
"T055790",
"T058670",
"T055779",
"T055778",
"T055789",
"T055777",
"T055788",
"T055787",
"T055786",
"T055785"
]
},
"release_date": "2026-06-24T22:00:00.000+00:00",
"title": "CVE-2026-57297"
},
{
"cve": "CVE-2026-57298",
"product_status": {
"known_affected": [
"T055784",
"T055783",
"T055782",
"T055781",
"T055780",
"T055790",
"T058670",
"T055779",
"T055778",
"T055789",
"T055777",
"T055788",
"T055787",
"T055786",
"T055785"
]
},
"release_date": "2026-06-24T22:00:00.000+00:00",
"title": "CVE-2026-57298"
},
{
"cve": "CVE-2026-57299",
"product_status": {
"known_affected": [
"T055784",
"T055783",
"T055782",
"T055781",
"T055780",
"T055790",
"T058670",
"T055779",
"T055778",
"T055789",
"T055777",
"T055788",
"T055787",
"T055786",
"T055785"
]
},
"release_date": "2026-06-24T22:00:00.000+00:00",
"title": "CVE-2026-57299"
},
{
"cve": "CVE-2026-57300",
"product_status": {
"known_affected": [
"T055784",
"T055783",
"T055782",
"T055781",
"T055780",
"T055790",
"T058670",
"T055779",
"T055778",
"T055789",
"T055777",
"T055788",
"T055787",
"T055786",
"T055785"
]
},
"release_date": "2026-06-24T22:00:00.000+00:00",
"title": "CVE-2026-57300"
},
{
"cve": "CVE-2026-57301",
"product_status": {
"known_affected": [
"T055794",
"T055793",
"T055792",
"T055791",
"T058670"
]
},
"release_date": "2026-06-24T22:00:00.000+00:00",
"title": "CVE-2026-57301"
},
{
"cve": "CVE-2026-57302",
"product_status": {
"known_affected": [
"T055794",
"T055793",
"T055792",
"T055791",
"T058670"
]
},
"release_date": "2026-06-24T22:00:00.000+00:00",
"title": "CVE-2026-57302"
},
{
"cve": "CVE-2026-57303",
"product_status": {
"known_affected": [
"T055794",
"T055793",
"T055792",
"T055791",
"T058670"
]
},
"release_date": "2026-06-24T22:00:00.000+00:00",
"title": "CVE-2026-57303"
},
{
"cve": "CVE-2026-57304",
"product_status": {
"known_affected": [
"T055794",
"T055793",
"T055792",
"T055791",
"T058670"
]
},
"release_date": "2026-06-24T22:00:00.000+00:00",
"title": "CVE-2026-57304"
},
{
"cve": "CVE-2026-57305",
"product_status": {
"known_affected": [
"T055794",
"T055793",
"T055792",
"T055791",
"T058670"
]
},
"release_date": "2026-06-24T22:00:00.000+00:00",
"title": "CVE-2026-57305"
},
{
"cve": "CVE-2026-57306",
"product_status": {
"known_affected": [
"T055794",
"T055793",
"T055792",
"T055791",
"T058670"
]
},
"release_date": "2026-06-24T22:00:00.000+00:00",
"title": "CVE-2026-57306"
},
{
"cve": "CVE-2026-57307",
"product_status": {
"known_affected": [
"T055794",
"T055793",
"T055792",
"T055791",
"T058670"
]
},
"release_date": "2026-06-24T22:00:00.000+00:00",
"title": "CVE-2026-57307"
}
]
}
Loading…
Loading…
Experimental. This forecast is provided for visualization only and may change without notice. Do not use it for operational decisions.
Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.
Sightings
| Author | Source | Type | Date | Other |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or observed by the user.
- Confirmed: The vulnerability has been validated from an analyst's perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
- Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
- Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
- Not confirmed: The user expressed doubt about the validity of the vulnerability.
- Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.
Loading…
The MITRE ATT&CK techniques below are AI-generated suggestions, inferred from the description of the
vulnerability by the CIRCL/vulnerability-attack-technique-classification-roberta-base
model, served locally by ML-Gateway.
They have not been verified by an analyst and are provided for guidance only.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
The approach is described in our paper Mapping CVEs to MITRE ATT&CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion.
Browse all ATT&CK techniques and the vulnerabilities related to each.
Loading…
Related by attack behaviour
Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.
Loading…