[TTD] Jenkins Controller Deserialization and CI/CD Control-Plane Abuse Exposure

Report Type: Threat-to-Detection
Threat Category: Jenkins Controller Deserialization and CI/CD Control-Plane Abuse Exposure
Assessment Date: June 15, 2026
Primary Impact Domain: CI/CD Control-Plane Integrity
Secondary Impact Domains: Credential Trust, Artifact Integrity, Production Release Governance, Cloud and Kubernetes Deployment Authority, Software Supply-Chain Assurance
Affected Asset Class: Jenkins Controllers, CI/CD Infrastructure, Build and Deployment Pipelines, Jenkins-Managed Credentials, Artifact and Release Workflows
Threat Objective Classification: Privileged Jenkins Request Abuse, User Impersonation, Credential Exposure, Controller-Side Execution, Job or Plugin Manipulation, Artifact Publication Abuse, and Downstream Deployment-Path Compromise

Published by: CyberDax LLC
Author: Edward “Tony” Dolley
Role: Founder / Principal Threat Researcher, CyberDax LLC
Publication Date: June 15, 2026
Publication Type: Cybersecurity Research Report / White Paper

BLUF

‍  Jenkins controller deserialization and CI/CD control-plane abuse exposure creates material business risk because attacker-controlled Jenkins configuration submission can become a path to user impersonation, privileged Jenkins request handling, Script Console execution, arbitrary controller file read, credential exposure, job manipulation, plugin modification, artifact publication, and downstream deployment-path abuse. The core risk is whether adversaries can move from Jenkins configuration handling into trusted CI/CD authority before the organization can validate controller version state, configuration activity, user context, credential exposure, controller integrity, job integrity, artifact provenance, and deployment history. Immediate executive action is required to upgrade affected Jenkins controllers, restrict administrative exposure, review Jenkins permissions, validate pipeline integrity, rotate credentials where compromise is suspected, and deploy behavior-led detection across Jenkins controller and downstream CI/CD telemetry.

Executive Risk Translation

Jenkins deserialization exposure shifts the business risk from routine application patching to uncertainty over whether a trusted software-delivery control plane can still be relied upon. If Jenkins controller activity, privileged requests, Script Console use, credential access, job changes, artifact publication, cloud activity, Kubernetes activity, and production deployments cannot be tied to reliable evidence, leadership may need to assume CI/CD trust was exposed until proven otherwise. That response can expand into emergency upgrade windows, release pauses, controller forensics, credential rotation, job and plugin review, artifact validation, downstream environment review, and executive reporting.

S5 Executive Risk Summary

Business Risk

Jenkins controller abuse can undermine CI/CD trust, credential control, artifact integrity, source-code workflow integrity, cloud deployment authority, Kubernetes deployment authority, and production change governance.

Technical Cause

The issue involves Jenkins deserializing attacker-controlled config.xml data in a way that may allow deserialized types from Jenkins core or installed plugins to handle HTTP requests afterward. The durable detection issue is the sequence from suspicious configuration submission into privileged Jenkins behavior, controller-side execution, credential access, or downstream CI/CD activity.

Threat Posture

This is strategically significant for organizations using Jenkins as a production CI/CD control plane, artifact publisher, deployment orchestrator, cloud automation path, Kubernetes deployment path, or secrets broker. It should be treated as Jenkins controller trust-boundary abuse, not as a narrow configuration request issue.

Executive Decision Requirement

Leadership should require affected-controller upgrade, exposure review, Jenkins permission review, Script Console access validation, credential rotation where warranted, pipeline and artifact integrity review, downstream cloud and Kubernetes validation, and deployment of the S25 detection logic.

S6 Executive Cost Summary

Jenkins controller deserialization and CI/CD control-plane abuse exposure creates financial exposure because the organization must determine whether Jenkins was used to impersonate users, issue privileged requests, access credentials, modify jobs, publish artifacts, or affect downstream deployment paths. The cost profile is higher than routine patching when Jenkins supports production releases, artifact generation, cloud deployment, Kubernetes deployment, source-code access, or shared credentials.

Response cost is driven by affected-controller inventory, upgrade validation, log review, permission review, Script Console review, job and plugin diffing, credential rotation, artifact validation, cloud and Kubernetes audit review, and release-history validation.

Low Impact Scenario

Rapid investigation confirms affected-version exposure or suspicious configuration-path activity without evidence of privileged Jenkins actions, Script Console access, credential exposure, controller file access, job changes, plugin changes, suspicious controller execution, rare egress, artifact publication, cloud activity, Kubernetes activity, or production deployment impact. Response remains limited to upgrade, exposure review, permission validation, targeted log review, short-term monitoring, and executive assurance. Estimated impact $25K - $150K.

Moderate Impact Scenario

Confirmed or strongly suspected abuse affects one or more production Jenkins controllers and includes suspicious configuration submission, possible user impersonation, privileged-path access, job changes, plugin changes, credential-path activity, sensitive controller file access, rare egress, or uncertainty over downstream Jenkins-linked activity. Response may require emergency maintenance, Jenkins and host forensics, credential rotation, job and plugin validation, artifact review, source-code audit, cloud identity review, Kubernetes audit review, and release validation. Estimated impact $150K - $1.2M.

High Impact Scenario

Jenkins controller abuse becomes an enterprise-impact event when there is confirmed Script Console execution, arbitrary controller file read, credential theft, malicious job modification, plugin persistence, unauthorized artifact publication, source-code abuse, cloud control-plane activity, Kubernetes deployment manipulation, production release compromise, or customer-facing software impact. Response may require controller rebuilds, broad credential rotation, artifact revocation or validation, release rollback or validation, cloud and Kubernetes incident response, legal review, customer communications, and board-level reporting. Estimated impact $1M - $8M+.

S6A Key Cost Drivers

·        Number and importance of affected Jenkins controllers.

·        Whether Jenkins supports production releases, artifacts, source code, cloud, Kubernetes, or regulated workloads.

·        Evidence of Script Console use, credential access, arbitrary file read, job change, plugin change, controller execution, rare egress, artifact publication, or deployment activity.

·        Availability of Jenkins audit logs, access logs, proxy or WAF logs, endpoint telemetry, DNS/proxy logs, artifact logs, cloud logs, Kubernetes logs, and release records.

·        Scope of Jenkins-managed credentials and downstream identities requiring review or rotation.

·        Completeness of approved administrator, job, plugin, release-window, maintenance-window, and egress inventories.

·        Business disruption caused by release pauses, job disablement, credential rotation, artifact validation, or production deployment review.

·        Customer, contractual, regulatory, or board-level exposure if artifact integrity or production release integrity cannot be proven.

S6B Compliance and Risk Context

Jenkins controller abuse may create compliance, contractual, regulatory, operational resilience, customer-notification, or software-supply-chain exposure when credential access, artifact manipulation, production deployment activity, regulated workload impact, or customer-facing software changes are confirmed or cannot be ruled out.

For production software delivery environments, the core governance question is whether the organization can prove that Jenkins users, jobs, plugins, credentials, artifacts, cloud actions, Kubernetes activity, and production deployments remained authorized during the exposure window.

Risk Register Entry

Risk Title

Jenkins Controller Deserialization and CI/CD Control-Plane Abuse Exposure

Risk Description

Affected Jenkins controllers may allow attacker-controlled configuration submission to create a path into user impersonation, privileged Jenkins request handling, Script Console execution, arbitrary controller file read, credential exposure, job manipulation, plugin modification, artifact publication, cloud activity, Kubernetes activity, or production release abuse.

Likelihood

Medium-High

Impact

High

Risk Rating

High

Annualized Risk Exposure

Estimated $150K - $1.2M+ for materially exposed Jenkins environments with affected controller versions, broad configuration permissions, production release workflows, incomplete logging, missing controller endpoint telemetry, broad Jenkins-managed credentials, or weak downstream identity mapping. Exposure may exceed $1M - $8M+ where abuse results in credential theft, artifact manipulation, production deployment impact, customer-facing software impact, legal review, customer communications, or board-level reporting.

S10 Threat Overview

Jenkins SECURITY-3707 / CVE-2026-53435 involves attacker-controlled config.xml submission and Jenkins deserialization behavior that can allow deserialized types from Jenkins core or installed plugins to handle HTTP requests afterward.

The activity becomes materially significant because Jenkins often acts as a software-delivery authority. A controller with access to jobs, credentials, artifacts, cloud roles, Kubernetes service accounts, source-code integrations, and production release workflows can convert a Jenkins-layer issue into a broader CI/CD trust problem.

This TTD treats the activity as Jenkins controller deserialization and CI/CD control-plane abuse exposure, not as a narrow Jenkins patching event.

S13 Targets and Exposure Surface

Primary Targets

Jenkins controllers running affected Jenkins versions.

Production Jenkins controllers supporting CI/CD, artifact publication, source-code integration, cloud deployment, Kubernetes deployment, secrets brokering, infrastructure automation, or production release workflows.

TeamCity On-Premises servers running versions earlier than 2025.11.7 and 2026.1.3, as applicable to the installed release branch.

Red Hat Ansible Automation Platform deployments using automation-controller for centralized infrastructure automation, job and workflow execution, project and source-control synchronization, credential use, execution-environment management, instance-group operation, container-group execution, Kubernetes or OpenShift automation, and downstream infrastructure or application deployment.

Higher-Risk Deployment Conditions

Jenkins controllers are broadly reachable.

Users have broad job, view, agent, or system configuration permissions.

Privileged users have Script Console access.

Jenkins stores long-lived credentials or deployment secrets.

Jenkins jobs can publish artifacts, push container images, deploy infrastructure, or alter production systems.

Jenkins audit logs, endpoint telemetry, job ownership, plugin inventory, or release-window records are incomplete.

An unauthenticated remote attacker can reach the affected TeamCity HTTP or HTTPS service and abuse the agent-polling protocol.

Ansible Automation Platform users, teams, organizations, projects, inventories, job templates, workflow job templates, instance groups, execution environments, credentials, notifications, or controller integrations have broader permissions than required.

Automation-controller can access sensitive infrastructure credentials, source-control credentials, execution-environment credentials, Kubernetes or OpenShift service-account tokens, namespace secrets, cloud credentials, deployment credentials, or other privileged automation material.

Automation-controller projects synchronize content from external source-control systems or execute automation content that can influence controller-side processing, job execution, execution-environment selection, container-group behavior, or downstream infrastructure changes.

Container groups or Kubernetes/OpenShift-backed execution paths permit user-controlled or insufficiently restricted execution specifications, service-account context, namespace access, or pod configuration.

Automation-controller audit records, controller web or task process telemetry, job and workflow ownership, credential provenance, project synchronization history, instance-group activity, receptor identity, Kubernetes or OpenShift audit records, or downstream deployment records are incomplete.

Exposure Surface

Jenkins configuration submission paths.

config.xml endpoints.

Job, view, agent, node, and system configuration paths.

Script Console.

Credential store.

Plugin manager.

User and security realm paths.

Controller filesystem.

Job definitions, pipeline scripts, shared libraries, workspaces, artifacts, source-code integrations, cloud deployment workflows, and Kubernetes deployment workflows.

TeamCity server interfaces and server-process context, including configuration, projects, builds, agents, plugins, artifacts, and connected integrations.

Red Hat Ansible Automation Platform automation-controller interfaces and controller services, including users, teams, organizations, inventories, projects, source-control synchronization, credentials, job templates, workflow job templates, schedules, notifications, execution environments, instance groups, container groups, receptor-connected execution paths, API and web interfaces, controller web and task processes, controller filesystem and configuration state, audit activity, and connected integrations.

Automation-controller credential and secret boundaries, including infrastructure credentials, machine credentials, source-control credentials, external-service credentials, execution-environment credentials, cloud credentials, Kubernetes or OpenShift service-account tokens, namespace secrets, and other automation material available to controller-managed jobs or integrations.

Kubernetes and OpenShift execution surfaces used by Ansible Automation Platform, including container-group pod specifications, namespaces, service accounts, secrets, execution pods, controller-to-cluster communication, workload creation, and downstream infrastructure or application changes.

Ansible Automation Platform-controlled project, workflow, job, inventory, notification, and external-integration paths where lower-trust input, insufficient authorization, cross-tenant access, credential misuse, server-side requests, controller-side execution, or privileged automation activity could affect controller integrity, credential trust, automation authority, or downstream systems.

S17 MITRE ATT&CK Chain Flow Mapping

Stage 1: Jenkins Controller Exposure and Configuration Abuse

Attacker-controlled configuration submission reaches an affected Jenkins controller under required access and permission conditions.

·        T1190 Exploit Public-Facing Application, applied conditionally where Jenkins is reachable from the attacker’s access position.

Stage 2: User Impersonation or Privileged Jenkins Request Handling

Deserialized object behavior enables follow-on HTTP request handling, user impersonation, or privileged Jenkins actions.

·        T1068 Exploitation for Privilege Escalation.

Stage 3: Script Console, Controller File Access, or Credential Exposure

The adversary attempts Script Console execution, controller-side command execution, arbitrary file read, credential access, token creation, or sensitive Jenkins file access.

·        T1059 Command and Scripting Interpreter.

·        T1552 Unsecured Credentials.

·        T1555 Credentials from Password Stores.

·        T1005 Data from Local System.

Stage 4: CI/CD Pipeline, Artifact, or Deployment-Path Abuse

The adversary uses Jenkins trust to modify jobs, alter plugins, publish artifacts, abuse source-code workflows, deploy to cloud or Kubernetes, or manipulate production release paths.

·        T1053 Scheduled Task/Job.

·        T1505 Server Software Component.

Conditional Technique Notes

T1105 Ingress Tool Transfer should only be applied if controller-side download, staging, or tool retrieval is observed.

T1565.002 Stored Data Manipulation should only be applied if artifact, job, configuration, deployment manifest, or release data manipulation is observed.

S18 Attack Path Narrative

An attacker reaches an affected Jenkins controller and satisfies the required access conditions.

The attacker submits controlled configuration data through config.xml or related configuration paths.

Jenkins deserializes allowed core or plugin-defined types.

The deserialized object behavior enables follow-on HTTP request handling.

The attacker attempts user impersonation or privileged Jenkins requests.

The attacker accesses Script Console, credentials, plugin manager, job configuration, node management, user management, or security realm paths.

The attacker reads controller files, accesses credentials, modifies jobs, changes plugins, or triggers controller-side execution.

The attacker uses Jenkins-held trust to affect artifacts, source-code workflows, cloud resources, Kubernetes workloads, or production deployments.

Defenders should detect this through correlated configuration submission, privileged Jenkins activity, controller host behavior, rare egress, and downstream CI/CD activity.

S20 TTP Analysis

Initial Access

Jenkins configuration handling is abused after the attacker reaches an affected Jenkins controller and satisfies the required permission conditions.

Execution

Execution may occur through Script Console, Groovy execution, job manipulation, Jenkins service-context process execution, shell execution, PowerShell execution, or build-step abuse.

Persistence

Persistence may occur through modified jobs, scheduled builds, build triggers, shared libraries, plugins, node configuration, user or token creation, credential additions, webhook changes, or altered deployment workflows.

Privilege Escalation

The deserialization path may allow attacker-controlled behavior to reach another user context or privileged Jenkins actions.

Defense Evasion

Attackers may blend into legitimate Jenkins workflows by using trusted users, normal configuration paths, existing jobs, approved-looking plugin names, or release windows.

Credential Access

Attackers may access Jenkins credential stores, controller secrets, job configurations, environment variables, API tokens, SSH keys, deployment keys, cloud credentials, Kubernetes credentials, source-code tokens, or artifact repository credentials.

Discovery

Attackers may inspect users, groups, permissions, jobs, credentials, plugins, nodes, workspaces, artifacts, source-code integrations, cloud roles, Kubernetes clusters, release jobs, and deployment targets.

Impact

Attackers may alter builds, publish unauthorized artifacts, compromise source-code workflows, deploy unauthorized infrastructure, alter Kubernetes workloads, trigger production releases, disrupt CI/CD operations, or damage artifact trust.

S20A — Adversary Tradecraft Summary

The durable tradecraft pattern is controller-trust conversion: attacker-controlled Jenkins configuration data enables privileged Jenkins behavior, which is then used to reach credentials, controller files, jobs, plugins, artifacts, cloud roles, Kubernetes service accounts, or release workflows. Detection should focus on that sequence rather than a single request string, CVE label, or proof-of-concept artifact.

S21 Detection Strategy Overview

Detection Philosophy

Detect Jenkins controller trust abuse through correlated behavior, not single indicators.

Primary Detection Anchors

Suspicious configuration submission, privileged Jenkins paths, Script Console activity, credential activity, sensitive controller file access, controller-side execution, rare egress, artifact publication, cloud activity, Kubernetes activity, and production release behavior.

Detection Prioritization Model

Prioritize events where configuration submission is followed by privileged Jenkins activity or downstream CI/CD actions within a bounded time window.

Correlation Strategy (Strict Enforcement)

Do not promote cloud-only, network-only, or endpoint-only anomalies to high confidence without Jenkins controller, user, job, identity, or time-window correlation.

Telemetry Prioritization

Prioritize Jenkins audit logs, URI-preserving web logs, endpoint process/file telemetry, DNS/proxy logs, artifact logs, cloud logs, Kubernetes logs, and release records.

Detection Design Constraints

Avoid detection designs based only on CVE name, single URI, user agent, exploit string, actor name, or IOC.

Baseline and Deployment Requirements

Baseline approved administrators, source networks, jobs, plugins, service accounts, command patterns, maintenance windows, release windows, and egress destinations.

Variant Resilience Requirements

Rules should remain useful for future Jenkins controller abuse paths that produce the same operational behavior.

Operational Detection Model

Run detections in hunt mode first, tune exceptions, validate joins, verify triage fields, then promote to alert mode.

Explicit Non-Deployment Guardrails

Do not deploy weak cloud-control-plane-only rules as Jenkins compromise detection. Do not claim exploit confirmation from isolated scanner traffic, generic web errors, or uncorrelated egress.


Figure

S22 Primary Detection Signals

Primary Detection Signals

POST requests to Jenkins configuration paths, including config.xml, createItem, doCreateItem, doConfigSubmit, job configuration, view configuration, or node configuration paths.

Configuration submission from unusual sources, unusual users, or outside maintenance windows.

Configuration submission followed by Script Console access, credential activity, plugin changes, job changes, user changes, node changes, or security realm changes.

Jenkins service account spawning shells, scripting engines, transfer tools, archive tools, remote-access utilities, or encoded commands.

Sensitive Jenkins file access involving credentials, secrets, jobs, plugins, users, workspaces, or build artifacts.

Supporting Detection Signals

Unusual authenticated-user context.

Unexpected forwarded user context.

Crumb anomalies where visible.

Rare controller egress.

Unexpected artifact publication.

Unexpected source-code, cloud, Kubernetes, or deployment activity using Jenkins-linked identities.

Exploit Attempt and Instability Signals

Repeated configuration-path errors.

Unusual HTTP status patterns around configuration submission.

Denied access to privileged Jenkins paths.

Scanner-like activity followed by authenticated Jenkins behavior.

Outbound Communication Signals

DNS, proxy, or network activity from Jenkins controllers to newly seen, rare, suspicious, or unapproved destinations.

Persistence and Post-Exploitation Signals (Conditional)

New or modified jobs, plugins, shared libraries, credentials, users, tokens, build triggers, node configuration, or deployment jobs.

Lateral Movement and Expansion Signals (Conditional)

Jenkins-linked credentials or service accounts used against source-code systems, artifact repositories, cloud accounts, Kubernetes clusters, or production deployment systems.

Signal Usage Constraints

Do not treat a single signal as compromise confirmation. Promote confidence when signals align by controller, user, source, job, identity, and time window.

S23 Telemetry Requirements

Required Telemetry

Jenkins audit logs.

Jenkins access logs where available.

Reverse-proxy logs.

WAF logs.

Load-balancer logs.

Endpoint process telemetry from Jenkins controllers.

Endpoint file telemetry from Jenkins controllers.

DNS logs.

Proxy or egress firewall logs.

Jenkins controller asset inventory.

Approved Jenkins administrator lookup.

Approved Jenkins source-network lookup.

Approved Jenkins job inventory.

Approved Jenkins plugin inventory.

Approved Jenkins service-account inventory.

Approved maintenance-window lookup.

Approved release-window lookup.

Strongly Recommended Telemetry

Source-code repository audit logs.

Artifact repository logs.

Container registry logs.

Cloud audit logs.

Kubernetes audit logs.

Secrets manager audit logs.

Identity provider logs.

EDR network telemetry.

NDR session telemetry.

CMDB records.

Cloud tags.

Kubernetes labels.

Jenkins credential metadata.

Jenkins job ownership metadata.

Recently seen domain enrichment.

Approved scanner and validation-source lookup.

Local Mapping Required

Jenkins controller identifier.

Jenkins hostname.

Jenkins base URL.

Jenkins username.

Jenkins role.

Jenkins action.

Job name.

Plugin name.

Credential identifier.

HTTP method.

URI path.

Source IP.

Forwarded source IP.

Authenticated user.

Forwarded user.

Jenkins crumb result where available.

Backend host.

Process name.

Parent process.

Command line.

Process user.

File path.

Destination domain.

Destination IP.

Artifact path.

Cloud account.

Cloud identity.

Kubernetes cluster.

Kubernetes namespace.

Deployment target.

Maintenance-window status.

Release-window status.

Approved administrator status.

Approved job status.

Approved plugin status.

Approved egress-destination status.

S24 Detection Opportunities and Gaps

Detection Opportunities

Suspicious configuration submission can be correlated with privileged Jenkins actions, controller execution, sensitive file access, rare egress, and downstream CI/CD activity.

Endpoint telemetry may reveal controller-side execution even when Jenkins audit logs are incomplete.

WAF and reverse-proxy logs may preserve configuration-path evidence when Jenkins-native logs are incomplete.

Artifact, cloud, Kubernetes, and source-code logs may reveal downstream abuse of Jenkins-linked identities.

Detection Gaps

Jenkins audit logs may be absent or incomplete.

Reverse proxies may not preserve full URI paths.

Endpoint telemetry may be missing from controllers.

Controller identity may not join cleanly across web, endpoint, network, and downstream logs.

Cloud, Kubernetes, artifact, and source-code activity may not map back to Jenkins identities or jobs.

Compensating Controls

Use WAF logs, reverse-proxy logs, load-balancer logs, Jenkins audit logs, endpoint telemetry, file telemetry, DNS logs, proxy logs, source-code logs, artifact logs, cloud logs, Kubernetes logs, release records, approved inventories, and change-control evidence.

Do not rely only on Jenkins version validation if suspicious activity occurred during the exposure window.

S25 Ultra-Tuned Detection Engineering Rules

NDR / Network Behavioral Analytics

Detection Viability Assessment

Production-deployable where Jenkins controller HTTP requests, reverse-proxy routing, WAF events, DNS queries, proxy sessions, authenticated-user headers, Jenkins crumb behavior, and destination-domain enrichment can be joined to the same Jenkins controller. Pure NetFlow is not sufficient because this detection requires Jenkins-specific URI visibility for config.xml, createItem, doCreateItem, doConfigSubmit, Script Console, credentials, plugin manager, user, node, security realm, and job configuration paths.

Rule

Jenkins Config XML Submission With Privileged Path, User Context, or Rare Egress Correlation

Rule Format

Production-deployable NDR / WAF / reverse-proxy behavioral correlation pattern requiring local query-language translation.

Detection Purpose

Detect suspicious Jenkins configuration submission activity that aligns with privileged Jenkins controller access, abnormal authenticated-user context, Script Console exposure, credential-path access, plugin-management access, node-management access, security realm access, or rare outbound communication from the same Jenkins controller.

Detection Logic

Trigger when a Jenkins controller receives POST activity to Jenkins configuration paths involving config.xml, createItem, doCreateItem, doConfigSubmit, item creation, job configuration, or description-submission endpoints from a source that is not an approved Jenkins administrator source or approved scanner.

Assign medium severity when suspicious configuration-path activity occurs against a Jenkins controller from an unapproved or unusual source.

Assign high severity when suspicious configuration-path activity is followed within 60 minutes by access to Script Console, credentials, plugin manager, node management, user management, build-agent management, security realm, or administrative paths on the same controller.

Assign high severity when suspicious configuration-path activity includes an unusual authenticated-user header, unexpected Jenkins crumb behavior, missing expected crumb validation context, invalid crumb result, or source/user mismatch for a Jenkins administrative action.

Promote to critical when suspicious configuration-path activity is followed within 60 minutes by rare outbound communication from the Jenkins controller, or when downstream telemetry confirms credential access, job modification, plugin modification, artifact publication, cloud deployment, Kubernetes activity, controller-side process execution, source-code activity, or production deployment activity.

Required Telemetry

Reverse-proxy logs.

WAF logs.

Load-balancer logs.

Web access logs.

Jenkins access logs where available.

DNS logs.

Proxy logs.

NDR session telemetry.

Authenticated-user header visibility where available.

Jenkins crumb or CSRF validation context where available.

Jenkins controller asset inventory.

Approved Jenkins administrator source lookup.

Approved Jenkins administrator user lookup.

Approved Jenkins scanner lookup.

Approved Jenkins maintenance-window lookup.

Approved Jenkins egress-destination lookup.

Recently seen destination-domain baseline.

Engineering Implementation Instructions

Map http_method, uri_path, query_string, source_ip, x_forwarded_for, x_forwarded_user, authenticated_user, jenkins_crumb_present, jenkins_crumb_result, user_agent, http_status, backend_host, backend_ip, jenkins_controller_id, src_host, dest_domain, dest_ip, dns_query, proxy_action, and timestamp.

Build ASSET_GROUP("jenkins_controllers") from CMDB records, DNS records, reverse-proxy routing, load-balancer target groups, cloud tags, Kubernetes ingress metadata, and Jenkins base URLs.

Create APPROVED_JENKINS_ADMIN_SOURCES, APPROVED_JENKINS_ADMIN_USERS, APPROVED_JENKINS_ADMIN_USER_SOURCE_MAP, APPROVED_JENKINS_SCANNERS, APPROVED_JENKINS_MAINTENANCE_WINDOWS, and APPROVED_JENKINS_EGRESS_DESTINATIONS.

Validate that the local WAF, reverse proxy, or load balancer preserves Jenkins URI paths and does not collapse job-path depth before alert mode.

Validate whether Jenkins crumb fields are available. If crumb fields are unavailable, do not block deployment; rely on URI, user, source, status, Jenkins audit, endpoint, egress, and downstream correlation.

Translate the query pattern into the target NDR, WAF, SIEM, proxy, or detection platform syntax using local lookup and join functions.

Treat TLS termination, URI visibility, backend-host joins, authenticated-user mapping, crumb mapping, egress baselining, allowlist tuning, and SOC triage routing as required local deployment work.

DRI Assessment

High resilience where full Jenkins URI visibility, controller identity, authenticated-user mapping, DNS/proxy telemetry, approved-source enrichment, and rare-destination baselining are available.

DRI

8.6 / 10

TCR Assessment

Operational confidence is moderate for standalone suspicious configuration-path activity and high when configuration activity aligns with privileged Jenkins paths, unusual authenticated-user context, crumb anomalies, or rare controller egress.

Operational TCR

8.2 / 10

Full-Telemetry TCR

9.2 / 10

Limitations

Encrypted traffic without WAF, reverse-proxy, CDN, or server-side HTTP logging may hide Jenkins URI paths. Jenkins crumb visibility is not guaranteed in all logging paths. Legitimate administrative automation may submit job configuration changes. High-severity and critical promotion require local correlation to privileged paths, authenticated-user context, egress, Jenkins audit events, endpoint telemetry, or downstream deployment evidence.

Detection Query Pattern

Production-deployable behavioral pattern pending local query-language translation:

DATASETS:

  ENV_WAF

  ENV_REVERSE_PROXY

  ENV_LOAD_BALANCER

  ENV_WEB_ACCESS

  ENV_JENKINS_ACCESS

  ENV_DNS

  ENV_PROXY

SCOPE:

  backend_host IN ASSET_GROUP("jenkins_controllers")

WINDOW:

  60 minutes

SIGNAL suspicious_config_submission:

  http_method = "POST"

  AND (

    uri_path MATCHES "^/job/.*/config\\.xml$"

    OR uri_path MATCHES "^/view/.*/job/.*/config\\.xml$"

    OR uri_path = "/config.xml"

    OR uri_path CONTAINS "/createItem"

    OR uri_path CONTAINS "/doCreateItem"

    OR uri_path CONTAINS "/doConfigSubmit"

    OR uri_path CONTAINS "/submitDescription"

  )

  AND source_ip NOT IN LOOKUP("APPROVED_JENKINS_ADMIN_SOURCES")

  AND source_ip NOT IN LOOKUP("APPROVED_JENKINS_SCANNERS")

  AND timestamp NOT IN LOOKUP("APPROVED_JENKINS_MAINTENANCE_WINDOWS")

SIGNAL suspicious_user_context:

  backend_host IN ASSET_GROUP("jenkins_controllers")

  AND uri_path CONTAINS "/config"

  AND (

    authenticated_user NOT IN LOOKUP("APPROVED_JENKINS_ADMIN_USERS")

    OR x_forwarded_user NOT IN LOOKUP("APPROVED_JENKINS_ADMIN_USERS")

    OR (authenticated_user, source_ip) NOT IN LOOKUP("APPROVED_JENKINS_ADMIN_USER_SOURCE_MAP")

    OR jenkins_crumb_result IN ("missing","invalid","unexpected")

  )

SIGNAL privileged_jenkins_path:

  backend_host IN ASSET_GROUP("jenkins_controllers")

  AND (

    uri_path CONTAINS "/script"

    OR uri_path CONTAINS "/scriptText"

    OR uri_path CONTAINS "/credentials"

    OR uri_path CONTAINS "/pluginManager"

    OR uri_path CONTAINS "/computer/"

    OR uri_path CONTAINS "/user/"

    OR uri_path CONTAINS "/manage"

    OR uri_path CONTAINS "/securityRealm"

  )

  AND source_ip NOT IN LOOKUP("APPROVED_JENKINS_ADMIN_SOURCES")

SIGNAL rare_controller_egress:

  src_host IN ASSET_GROUP("jenkins_controllers")

  AND dest_domain NOT IN LOOKUP("APPROVED_JENKINS_EGRESS_DESTINATIONS")

  AND dest_domain NOT IN LOOKUP("APPROVED_BUSINESS_DOMAINS")

  AND (

    dest_domain_age_days < ENV_NEW_DOMAIN_AGE_DAYS

    OR domain_reputation IN ("unknown","suspicious","malicious")

    OR dest_country NOT IN LOOKUP("APPROVED_EGRESS_COUNTRIES")

  )

  AND proxy_action IN ("allowed","proxied","connected")

CORRELATION:

  suspicious_config_submission NEAR (

    suspicious_user_context

    OR privileged_jenkins_path

    OR rare_controller_egress

  )

  BY backend_host

  WITHIN 60 minutes

OUTPUT:

  backend_host

  source_ip

  x_forwarded_for

  authenticated_user

  x_forwarded_user

  user_agent

  uri_path

  http_method

  http_status

  jenkins_crumb_result

  dest_domain

  dest_ip

  first_seen

  last_seen

SentinelOne

Detection Viability Assessment

Production-deployable where SentinelOne covers Jenkins controllers and captures process creation, parent process, command line, process user, file access, file modification, and network telemetry. This rule is strongest on self-managed Jenkins controllers, dedicated Jenkins VMs, and container hosts where Jenkins controller processes can be separated from normal build-agent execution.

Rule

Jenkins Controller Service Context Execution With Sensitive Path or Egress Behavior

Rule Format

SentinelOne Deep Visibility query pattern for Jenkins controller host behavior requiring local field validation.

Detection Purpose

Detect suspicious Jenkins controller-side process execution, sensitive Jenkins file access, or outbound tooling from the Jenkins service context that may indicate Script Console execution, malicious job execution, controller compromise, or post-exploitation activity following configuration abuse.

Detection Logic

Trigger when a Jenkins controller records shell, scripting, transfer, archive, remote-access, credential-access, or encoding-related process execution from the Jenkins service account, Jenkins Java process tree, Jenkins controller service wrapper, or containerized Jenkins controller process.

Assign medium severity for suspicious Jenkins service-context process execution.

Assign high severity when process execution includes outbound transfer tools, encoded command execution, interactive shell behavior, sensitive Jenkins file access, credential file access, plugin modification, or execution outside approved job patterns.

Promote to critical when correlated with Jenkins Script Console access, config.xml submission activity, credential-store access, plugin modification, job reconfiguration, rare egress, artifact publication, cloud deployment, Kubernetes activity, source-code activity, or production deployment activity.

Required Telemetry

SentinelOne process telemetry.

SentinelOne command-line telemetry.

SentinelOne parent process telemetry.

SentinelOne file telemetry.

SentinelOne network telemetry.

Jenkins controller endpoint group.

Jenkins service account mapping.

Approved Jenkins build-command lookup.

Approved Jenkins maintenance-window lookup.

Approved Jenkins deployment-automation lookup.

Approved Jenkins plugin-maintenance lookup.

Engineering Implementation Instructions

Map EndpointName, EndpointId, AgentUuid, ProcessName, ProcessImagePath, ParentProcessName, ParentProcessImagePath, ProcessUser, CmdLine, FilePath, FileEventType, DstIp, DstPort, DstDomain, and EventTime.

Create ENV_JENKINS_CONTROLLERS and ENV_JENKINS_SERVICE_USERS.

Validate local Jenkins process names, including java, java.exe, jenkins, jenkins.exe, jenkins.war, winstone, wrapper.exe, container runtime parent processes, and systemd service paths.

Create exceptions for approved build commands, backup scripts, maintenance scripts, plugin update scripts, release deployment tooling, and vulnerability validation workflows.

Run in hunt mode before alert mode to baseline normal Jenkins job execution on controllers.

Treat endpoint grouping, service-account mapping, approved command exceptions, maintenance-window suppression, plugin-maintenance suppression, and alert routing as required local deployment work.

DRI Assessment

High where Jenkins controllers have SentinelOne coverage with process lineage, command-line, file, and network telemetry enabled.

DRI

8.9 / 10

TCR Assessment

Strong for suspicious controller-side execution when scoped to Jenkins controllers. Strongest when correlated with Jenkins audit logs, reverse-proxy activity, sensitive file access, or rare egress.

Operational TCR

8.4 / 10

Full-Telemetry TCR

9.4 / 10

Limitations

Legitimate Jenkins jobs may execute shell interpreters, build tools, transfer utilities, archive utilities, and deployment commands. This rule must be scoped to Jenkins controllers and tuned against approved job patterns before alert-mode deployment. Build-agent behavior should be covered by a separate agent-scoped rule if needed.

Detection Query Pattern

SentinelOne Deep Visibility pattern with local field mapping required:

EndpointName IN ENV_JENKINS_CONTROLLERS

AND (

  ProcessUser IN ENV_JENKINS_SERVICE_USERS

  OR SrcProcName IN ("java","java.exe","jenkins","jenkins.exe","winstone","wrapper.exe")

  OR SrcProcCmdLine CONTAINS "jenkins.war"

)

AND TgtProcName IN (

  "sh","bash","dash","zsh","cmd.exe","powershell.exe","pwsh.exe",

  "python","python3","perl","ruby","groovy","curl","wget","nc","ncat",

  "socat","ssh","scp","tar","zip","7z","openssl","certutil.exe","bitsadmin.exe"

)

AND CmdLine NOT IN LOOKUP("APPROVED_JENKINS_BUILD_COMMAND_PATTERNS")

AND CmdLine NOT IN LOOKUP("APPROVED_JENKINS_DEPLOYMENT_COMMAND_PATTERNS")

AND EventTime NOT IN LOOKUP("APPROVED_JENKINS_MAINTENANCE_WINDOWS")

AND (

  CmdLine CONTAINS "curl "

  OR CmdLine CONTAINS "wget "

  OR CmdLine CONTAINS "powershell -enc"

  OR CmdLine CONTAINS "FromBase64String"

  OR CmdLine CONTAINS "bash -c"

  OR CmdLine CONTAINS "/bin/sh -c"

  OR CmdLine CONTAINS "nc "

  OR CmdLine CONTAINS "ncat "

  OR CmdLine CONTAINS "credentials.xml"

  OR CmdLine CONTAINS "/var/lib/jenkins/secrets"

  OR CmdLine CONTAINS "/var/lib/jenkins/jobs/"

  OR CmdLine CONTAINS "/var/lib/jenkins/plugins/"

  OR CmdLine CONTAINS "C:\\ProgramData\\Jenkins\\.jenkins\\secrets"

  OR CmdLine CONTAINS "C:\\ProgramData\\Jenkins\\.jenkins\\jobs"

  OR CmdLine CONTAINS "C:\\ProgramData\\Jenkins\\.jenkins\\plugins"

  OR DstDomain NOT IN LOOKUP("APPROVED_JENKINS_EGRESS_DESTINATIONS")

)

OUTPUT:

  EndpointName

  ProcessUser

  SrcProcName

  TgtProcName

  CmdLine

  ParentProcessName

  FilePath

  FileEventType

  DstIp

  DstDomain

  EventTime

Splunk

Detection Viability Assessment

Production-deployable where Splunk ingests Jenkins audit logs, reverse-proxy or WAF logs, endpoint process and file telemetry, DNS/proxy logs, source-code logs, artifact repository logs, and cloud or Kubernetes logs where Jenkins has downstream access.

Rule

Jenkins Config XML Submission Followed by Script Console Credential or Controller Execution

Rule Format

Splunk SPL production correlation search with local index, sourcetype, macro, and lookup mapping.

Detection Purpose

Detect suspicious Jenkins config.xml or job configuration submission followed by privileged Jenkins activity, Script Console access, credential access, plugin or job modification, controller-side execution, sensitive Jenkins file activity, rare egress, or downstream CI/CD activity.

Detection Logic

Trigger when suspicious Jenkins configuration-path activity occurs and is followed within 60 minutes by one or more privileged Jenkins control-plane signals or Jenkins controller host signals.

Assign high severity when suspicious configuration submission aligns with Script Console access, credential access, API token creation, job reconfiguration, plugin change, Jenkins service-account process execution, sensitive Jenkins file access, unusual authenticated-user context, or rare controller egress.

Promote to critical when downstream artifact publication, source-code activity, cloud deployment, Kubernetes activity, or production deployment activity occurs using Jenkins-linked identity outside an approved release window.

Required Telemetry

Jenkins audit logs.

Jenkins access logs where available.

Reverse-proxy logs.

WAF logs.

Endpoint process logs.

Endpoint file logs.

DNS logs.

Proxy logs.

Source-code repository logs.

Artifact repository logs.

Cloud audit logs where applicable.

Kubernetes audit logs where applicable.

Approved Jenkins administrator lookup.

Approved Jenkins service-account lookup.

Approved maintenance-window lookup.

Approved release-window lookup.

Approved egress-destination lookup.

Approved Jenkins job lookup.

Approved Jenkins plugin lookup.

Engineering Implementation Instructions

Map indexes and sourcetypes for Jenkins audit logs, Jenkins access logs, proxy/WAF logs, EDR process logs, EDR file logs, DNS/proxy logs, source-code logs, artifact logs, cloud logs, and Kubernetes logs.

Normalize jenkins_controller, username, jenkins_action, role, uri_path, http_method, src_ip, x_forwarded_for, x_forwarded_user, authenticated_user, jenkins_crumb_result, user_agent, job_name, plugin_name, credential_id, process_name, parent_process_name, process_user, command_line, file_path, dest_domain, artifact_path, cloud_account, cluster_name, deployment_target, and _time.

Create lookups for approved administrators, approved admin sources, approved scanners, approved service accounts, approved maintenance windows, approved release windows, approved plugins, approved jobs, approved command patterns, approved egress destinations, Jenkins-linked cloud identities, Jenkins-linked Kubernetes service accounts, and Jenkins-linked artifact identities.

Create Splunk macros for local field normalization and maintenance-window evaluation before alert-mode deployment.

Validate that Jenkins controller host identity can join web, audit, endpoint, DNS/proxy, artifact, and cloud/Kubernetes events.

Run in hunt mode against at least 14 to 30 days of history to tune approved release activity, plugin maintenance, backup jobs, build automation, and administrative workflows.

Treat local index mapping, field normalization, lookup creation, join validation, false-positive baseline, macro creation, and SOC workflow routing as required local deployment work.

DRI Assessment

High where Splunk can join Jenkins web, audit, endpoint, network, artifact, and downstream deployment telemetry by controller, user, service account, job, and time window.

DRI

9.1 / 10

TCR Assessment

High when configuration submission is followed by privileged Jenkins behavior and controller host activity. Highest when downstream artifact or deployment telemetry is included.

Operational TCR

8.7 / 10

Full-Telemetry TCR

9.5 / 10

Limitations

Effectiveness depends on local field normalization and Jenkins audit quality. Legitimate administrative automation may require exceptions. Critical promotion requires downstream artifact, cloud, Kubernetes, or deployment telemetry.

Detection Query Pattern

Splunk SPL pattern requiring local lookup, macro, index, and sourcetype mapping:

(

search index=ENV_WEB_INDEX sourcetype=ENV_REVERSE_PROXY_OR_WAF_SOURCETYPE

dest_host IN ASSET_GROUP("jenkins_controllers")

http_method="POST"

(

  uri_path="*/config.xml"

  OR uri_path="*/createItem*"

  OR uri_path="*/doCreateItem*"

  OR uri_path="*/doConfigSubmit*"

  OR uri_path="*/submitDescription*"

)

NOT [ | inputlookup APPROVED_JENKINS_ADMIN_SOURCES | fields src_ip ]

NOT [ | inputlookup APPROVED_JENKINS_SCANNERS | fields src_ip ]

| eval normalized_controller=coalesce(dest_host,backend_host,host)

| eval normalized_user=coalesce(authenticated_user,x_forwarded_user,username)

| eval signal="suspicious_config_submission"

| table _time normalized_controller normalized_user src_ip x_forwarded_for user_agent uri_path http_method status jenkins_crumb_result signal

)

| append [

search index=ENV_JENKINS_AUDIT_INDEX sourcetype=ENV_JENKINS_AUDIT_SOURCETYPE

jenkins_action IN ("script_console_access","scriptText_execute","credential_read","credential_update","api_token_create","job_config_update","plugin_install","plugin_update","plugin_disable","user_impersonation","admin_login","node_config_update","security_realm_update")

| eval normalized_controller=coalesce(jenkins_controller,host)

| eval normalized_user=coalesce(username,user)

| eval signal=jenkins_action

| table _time normalized_controller normalized_user src_ip job_name plugin_name credential_id jenkins_action signal

]

| append [

search index=ENV_EDR_PROCESS_INDEX sourcetype=ENV_EDR_PROCESS_SOURCETYPE

host IN ASSET_GROUP("jenkins_controllers")

(

  process_user IN [ | inputlookup JENKINS_SERVICE_ACCOUNTS | fields process_user ]

  OR parent_process_name IN ("java","java.exe","jenkins","jenkins.exe","winstone","wrapper.exe")

)

process_name IN ("sh","bash","dash","zsh","cmd.exe","powershell.exe","pwsh.exe","python","python3","perl","ruby","groovy","curl","wget","nc","ncat","socat","ssh","scp","tar","zip","7z","openssl","certutil.exe","bitsadmin.exe")

NOT [ | inputlookup APPROVED_JENKINS_COMMAND_PATTERNS | fields command_line ]

| eval normalized_controller=host

| eval signal="jenkins_controller_service_execution"

| table _time normalized_controller process_user process_name parent_process_name command_line signal

]

| append [

search index=ENV_EDR_FILE_INDEX sourcetype=ENV_EDR_FILE_SOURCETYPE

host IN ASSET_GROUP("jenkins_controllers")

(

  file_path="*/credentials.xml"

  OR file_path="*/secrets/*"

  OR file_path="*/jobs/*/config.xml"

  OR file_path="*/plugins/*"

  OR file_path="*/users/*/config.xml"

)

event_action IN ("read","open","modify","create","rename","write")

| eval normalized_controller=host

| eval signal="sensitive_jenkins_file_activity"

| table _time normalized_controller file_path event_action process_name process_user signal

]

| append [

search index=ENV_DNS_OR_PROXY_INDEX

src_host IN ASSET_GROUP("jenkins_controllers")

NOT [ | inputlookup APPROVED_JENKINS_EGRESS_DESTINATIONS | fields dest_domain ]

NOT [ | inputlookup APPROVED_BUSINESS_DOMAINS | fields dest_domain ]

| eval normalized_controller=src_host

| eval signal="rare_jenkins_controller_egress"

| table _time normalized_controller dest_domain dest_ip signal

]

| bin _time span=60m

| stats

    values(signal) as signals

    values(src_ip) as src_ips

    values(x_forwarded_for) as x_forwarded_for

    values(user_agent) as user_agents

    values(uri_path) as uri_paths

    values(normalized_user) as users

    values(jenkins_crumb_result) as crumb_results

    values(job_name) as jobs

    values(plugin_name) as plugins

    values(credential_id) as credentials

    values(process_name) as processes

    values(parent_process_name) as parent_processes

    values(command_line) as command_lines

    values(file_path) as file_paths

    values(dest_domain) as dest_domains

    min(_time) as first_seen

    max(_time) as last_seen

  by normalized_controller _time

| eval has_config=if(mvfind(signals,"suspicious_config_submission")>=0,1,0)

| eval has_privileged=if(

    mvfind(signals,"script_console_access")>=0

    OR mvfind(signals,"scriptText_execute")>=0

    OR mvfind(signals,"credential_read")>=0

    OR mvfind(signals,"credential_update")>=0

    OR mvfind(signals,"api_token_create")>=0

    OR mvfind(signals,"job_config_update")>=0

    OR mvfind(signals,"plugin_install")>=0

    OR mvfind(signals,"plugin_update")>=0

    OR mvfind(signals,"plugin_disable")>=0

    OR mvfind(signals,"user_impersonation")>=0

    OR mvfind(signals,"node_config_update")>=0

    OR mvfind(signals,"security_realm_update")>=0

    OR mvfind(signals,"jenkins_controller_service_execution")>=0

    OR mvfind(signals,"sensitive_jenkins_file_activity")>=0

    OR mvfind(signals,"rare_jenkins_controller_egress")>=0,

    1,0

  )

| where has_config=1 AND has_privileged=1

| lookup APPROVED_JENKINS_MAINTENANCE_WINDOWS normalized_controller OUTPUT in_maintenance

| where isnull(in_maintenance)

| eval severity="high"

| eval cyberdax_rule="Jenkins Config XML Submission Followed by Script Console Credential or Controller Execution"

| table first_seen last_seen normalized_controller severity signals src_ips x_forwarded_for users crumb_results user_agents uri_paths jobs plugins credentials processes parent_processes command_lines file_paths dest_domains cyberdax_rule

Elastic

Detection Viability Assessment

Production-deployable where Elastic has Jenkins audit events, reverse-proxy or WAF events, endpoint process and file events, DNS/proxy events, and enrichment linking Jenkins controller identity to host identity. Exception logic must be implemented using Elastic exception lists, value lists, event filters, or equivalent local rule exceptions.

Rule

Jenkins Config XML Request to Privileged Controller Activity Sequence

Rule Format

Elastic EQL production sequence with Elastic exception lists, value lists, and local ECS mapping.

Detection Purpose

Detect suspicious Jenkins configuration-path activity followed by privileged Jenkins actions, controller-side execution, sensitive Jenkins file activity, or rare outbound communication.

Detection Logic

Trigger when a suspicious Jenkins configuration-path request is followed within 60 minutes by Script Console access, credential access, job or plugin changes, Jenkins service-account process execution, sensitive Jenkins file activity, or rare-destination network activity.

Assign high severity when the sequence occurs on a production Jenkins controller outside approved maintenance.

Promote to critical when the same controller, Jenkins user, Jenkins service account, job, artifact identity, cloud identity, or release workflow is tied to artifact publication, cloud deployment, Kubernetes activity, or production deployment outside approved release windows.

Required Telemetry

Reverse-proxy events.

WAF events.

Jenkins audit events.

Endpoint process events.

Endpoint file events.

DNS or proxy events.

Jenkins controller asset enrichment.

Elastic value list for Jenkins controllers.

Elastic value list for approved Jenkins administrator sources.

Elastic value list for approved scanners.

Elastic value list for approved Jenkins service accounts.

Elastic value list for approved egress destinations.

Elastic exception list for approved maintenance windows.

Elastic exception list for approved command patterns.

Engineering Implementation Instructions

Map event.dataset, url.path, http.request.method, source.ip, user_agent.original, host.name, jenkins.controller.id, jenkins.user.name, jenkins.action, jenkins.job.name, jenkins.plugin.name, jenkins.credential.id, process.name, process.command_line, process.parent.name, user.name, file.path, event.action, destination.domain, and @timestamp.

Create Elastic value lists for Jenkins controllers, approved Jenkins administrator CIDRs, approved scanners, approved Jenkins service accounts, approved egress destinations, approved plugins, and approved jobs.

Create Elastic exception rules for approved maintenance windows and approved command patterns if local Elastic licensing or rule design supports exception-based suppression.

If Elastic cannot express a maintenance-window exception directly in EQL, implement maintenance-window suppression through rule exceptions, alert suppression, post-processing, or detection-engineering workflow logic.

Validate join keys between proxy/WAF events, Jenkins audit events, endpoint events, and DNS/proxy events before alert mode.

Treat local ECS mapping, value-list creation, exception-list creation, join-key validation, alert severity tuning, historical baselining, and rule-action routing as required local deployment work.

DRI Assessment

High where Jenkins web, audit, endpoint, and network events share reliable controller identity.

DRI

8.8 / 10

TCR Assessment

Strong when suspicious Jenkins configuration request is followed by privileged Jenkins behavior or endpoint execution. Weaker where Jenkins audit events are absent.

Operational TCR

8.3 / 10

Full-Telemetry TCR

9.3 / 10

Limitations

EQL sequence quality depends on reliable join keys. Jenkins audit events may require custom ingestion. Legitimate automation must be exceptioned. Critical promotion requires downstream artifact or deployment correlation. Maintenance-window suppression may require rule exceptions or post-detection suppression depending on local Elastic capabilities.

Detection Query Pattern

Elastic EQL sequence pattern with value-list and exception-list placeholders requiring local implementation:

sequence by host.name with maxspan=60m

[ any where

  event.dataset in ("ENV_REVERSE_PROXY_DATASET","ENV_WAF_DATASET","ENV_WEB_ACCESS_DATASET") and

  http.request.method == "POST" and

  (

    wildcard(url.path, "*/config.xml") or

    wildcard(url.path, "*/createItem*") or

    wildcard(url.path, "*/doCreateItem*") or

    wildcard(url.path, "*/doConfigSubmit*") or

    wildcard(url.path, "*/submitDescription*")

  ) and

  not source.ip in $APPROVED_JENKINS_ADMIN_SOURCES and

  not source.ip in $APPROVED_JENKINS_SCANNERS

]

[ any where

  (

    event.dataset == "ENV_JENKINS_AUDIT_DATASET" and

    jenkins.action in (

      "script_console_access",

      "scriptText_execute",

      "credential_read",

      "credential_update",

      "api_token_create",

      "job_config_update",

      "plugin_install",

      "plugin_update",

      "plugin_disable",

      "user_impersonation",

      "node_config_update",

      "security_realm_update"

    )

  )

  or

  (

    event.category == "process" and

    host.name in $JENKINS_CONTROLLERS and

    (

      user.name in $JENKINS_SERVICE_ACCOUNTS or

      process.parent.name in ("java","java.exe","jenkins","jenkins.exe","winstone","wrapper.exe")

    ) and

    process.name in ("sh","bash","dash","zsh","cmd.exe","powershell.exe","pwsh.exe","python","python3","perl","ruby","groovy","curl","wget","nc","ncat","socat","ssh","scp","tar","zip","7z","openssl","certutil.exe","bitsadmin.exe") and

    not process.command_line in $APPROVED_JENKINS_COMMAND_PATTERNS

  )

  or

  (

    event.category == "file" and

    host.name in $JENKINS_CONTROLLERS and

    (

      wildcard(file.path, "*/credentials.xml") or

      wildcard(file.path, "*/secrets/*") or

      wildcard(file.path, "*/jobs/*/config.xml") or

      wildcard(file.path, "*/plugins/*") or

      wildcard(file.path, "*/users/*/config.xml")

    ) and

    event.action in ("open","read","modification","creation","rename","write")

  )

  or

  (

    event.category == "network" and

    host.name in $JENKINS_CONTROLLERS and

    not destination.domain in $APPROVED_JENKINS_EGRESS_DESTINATIONS

  )

]

until

[ any where

  event.dataset == "ENV_CHANGE_CONTROL_DATASET" and

  event.action in ("approved_jenkins_maintenance_start","approved_release_window_start")

]

QRadar

Detection Viability Assessment

Production-deployable where QRadar parses Jenkins audit logs, reverse-proxy or WAF logs, EDR logs, DNS/proxy logs, source-code logs, artifact logs, and cloud/Kubernetes logs into reliable custom properties. This should be implemented as building blocks with an offense rule. The AQL patterns below are validation searches for building-block logic, not three separate standalone production alerts.

Rule

Jenkins Config XML Abuse With Privileged Controller Activity Offense

Rule Format

QRadar building-block and offense-rule implementation pattern with AQL validation searches.

Detection Purpose

Correlate suspicious Jenkins configuration-path activity with privileged Jenkins actions, controller-side process execution, sensitive Jenkins file access, rare egress, or downstream deployment activity.

Detection Logic

Trigger building block one when a Jenkins controller receives suspicious POST activity to config.xml, createItem, doCreateItem, doConfigSubmit, or related job configuration paths.

Trigger building block two when Jenkins audit telemetry shows Script Console access, credential access, API token changes, job configuration changes, plugin changes, node changes, security realm changes, or user impersonation.

Trigger building block three when endpoint or network telemetry shows Jenkins service-account process execution, sensitive Jenkins file activity, or rare controller egress.

Create a high-severity offense when building block one and either building block two or building block three occur on the same Jenkins controller within 60 minutes.

Promote to critical when artifact publication, cloud deployment, Kubernetes activity, source-code activity, or production deployment activity occurs with Jenkins-linked identity within 120 minutes.

Required Telemetry

Jenkins audit logs.

Reverse-proxy logs.

WAF logs.

Endpoint process logs.

Endpoint file logs.

DNS logs.

Proxy logs.

Artifact repository logs where applicable.

Cloud audit logs where applicable.

Kubernetes audit logs where applicable.

Jenkins controller reference set.

Approved administrator reference set.

Approved scanner reference set.

Approved maintenance-window reference set.

Approved egress-destination reference set.

Approved Jenkins service-account reference set.

Engineering Implementation Instructions

Create custom properties for JENKINS_CONTROLLER, URLPATH, HTTP_METHOD, SOURCEIP, USERNAME, JENKINS_ACTION, JOB_NAME, PLUGIN_NAME, CREDENTIAL_ID, PROCESSNAME, COMMANDLINE, FILEPATH, DESTINATIONDOMAIN, ARTIFACT_PATH, CLOUD_ACCOUNT, CLUSTER_NAME, and DEPLOYMENT_TARGET.

Create reference sets for Jenkins controllers, approved administrators, approved admin sources, approved scanners, approved maintenance windows, approved release windows, approved plugins, approved jobs, approved command patterns, approved egress destinations, and Jenkins service accounts.

Validate DSM parsing for each log source before enabling offense correlation.

Test each building block independently with historical data.

Treat DSM parsing, custom property creation, reference-set loading, building-block validation, offense magnitude, ownership routing, and suppression workflow as required local deployment work.

DRI Assessment

Moderate to high where QRadar custom properties and reference sets are reliable.

DRI

8.3 / 10

TCR Assessment

Strong when Jenkins configuration-path activity, privileged Jenkins actions, and controller host behavior can be joined by controller identity. Lower when Jenkins audit parsing is incomplete.

Operational TCR

8.0 / 10

Full-Telemetry TCR

9.1 / 10

Limitations

QRadar effectiveness depends on DSM parsing quality, custom property accuracy, reference-set hygiene, and offense-rule correlation. Weak URI parsing or missing Jenkins audit logs will materially reduce confidence.

Detection Query Pattern

QRadar building-block validation searches and offense logic:

BUILDING BLOCK ONE VALIDATION SEARCH:

SELECT QIDNAME(qid) AS event_name, JENKINS_CONTROLLER, URLPATH, HTTP_METHOD, SOURCEIP, USERNAME, starttime

FROM events

WHERE REFERENCESETCONTAINS('ENV_JENKINS_CONTROLLERS', JENKINS_CONTROLLER)

AND HTTP_METHOD = 'POST'

AND (

  LOWER(URLPATH) LIKE '%/config.xml'

  OR LOWER(URLPATH) LIKE '%/createitem%'

  OR LOWER(URLPATH) LIKE '%/docreateitem%'

  OR LOWER(URLPATH) LIKE '%/doconfigsubmit%'

  OR LOWER(URLPATH) LIKE '%/submitdescription%'

)

AND NOT REFERENCESETCONTAINS('ENV_APPROVED_JENKINS_ADMIN_SOURCES', SOURCEIP)

AND NOT REFERENCESETCONTAINS('ENV_APPROVED_JENKINS_SCANNERS', SOURCEIP)

LAST 60 MINUTES

BUILDING BLOCK TWO VALIDATION SEARCH:

SELECT QIDNAME(qid) AS event_name, JENKINS_CONTROLLER, USERNAME, JENKINS_ACTION, JOB_NAME, PLUGIN_NAME, CREDENTIAL_ID, starttime

FROM events

WHERE REFERENCESETCONTAINS('ENV_JENKINS_CONTROLLERS', JENKINS_CONTROLLER)

AND JENKINS_ACTION IN (

  'script_console_access',

  'scriptText_execute',

  'credential_read',

  'credential_update',

  'api_token_create',

  'job_config_update',

  'plugin_install',

  'plugin_update',

  'plugin_disable',

  'user_impersonation',

  'node_config_update',

  'security_realm_update'

)

LAST 60 MINUTES

BUILDING BLOCK THREE VALIDATION SEARCH:

SELECT QIDNAME(qid) AS event_name, JENKINS_CONTROLLER, PROCESSNAME, COMMANDLINE, FILEPATH, DESTINATIONDOMAIN, starttime

FROM events

WHERE REFERENCESETCONTAINS('ENV_JENKINS_CONTROLLERS', JENKINS_CONTROLLER)

AND (

  PROCESSNAME IN ('sh','bash','dash','zsh','cmd.exe','powershell.exe','pwsh.exe','python','python3','perl','ruby','groovy','curl','wget','nc','ncat','ssh','scp','certutil.exe','bitsadmin.exe')

  OR LOWER(FILEPATH) LIKE '%/credentials.xml'

  OR LOWER(FILEPATH) LIKE '%/secrets/%'

  OR LOWER(FILEPATH) LIKE '%/jobs/%/config.xml'

  OR LOWER(FILEPATH) LIKE '%/users/%/config.xml'

  OR NOT REFERENCESETCONTAINS('ENV_APPROVED_JENKINS_EGRESS_DESTINATIONS', DESTINATIONDOMAIN)

)

LAST 60 MINUTES

OFFENSE RULE CONDITION:

Building block one and either building block two or building block three occur on the same JENKINS_CONTROLLER within 60 minutes outside approved maintenance.

CRITICAL PROMOTION CONDITION:

Artifact, cloud, Kubernetes, source-code, or production deployment activity occurs with a Jenkins-linked identity within 120 minutes of the high-severity offense.

SIGMA

Detection Viability Assessment

Production-deployable after conversion and local enrichment where endpoint process telemetry is collected from Jenkins controllers. SIGMA is appropriate for portable host detection of suspicious Jenkins service-context execution and should be promoted through the target SIEM only when joined with Jenkins audit or web telemetry.

Rule

Jenkins Controller Suspicious Service Context Execution

Rule Format

SIGMA portable process-creation rule requiring target-SIEM conversion, Jenkins host enrichment, and local exception logic.

Detection Purpose

Detect suspicious shell, scripting, transfer, remote-access, archive, encoding, or credential-related process execution from Jenkins controller service context.

Detection Logic

Trigger when a Jenkins parent process or Jenkins service account spawns suspicious interpreters, transfer tools, remote-access tools, encoded PowerShell, shell wrappers, archive utilities, or credential-access commands on a Jenkins controller.

Assign medium severity for standalone converted rule matches.

Promote to high severity in the target SIEM when correlated with Jenkins config.xml activity, Script Console access, credential access, job changes, plugin changes, sensitive file reads, or rare egress.

Required Telemetry

Process creation telemetry.

Command-line telemetry.

Parent process telemetry.

User field.

Host asset enrichment.

Jenkins service account enrichment.

Approved Jenkins command-pattern exceptions.

Approved Jenkins maintenance-window exceptions.

Engineering Implementation Instructions

Convert to the target SIEM.

Map Image, ParentImage, CommandLine, User, Hostname, CurrentDirectory, EventID, and process creation timestamp.

Add Jenkins controller asset enrichment after conversion.

Add approved Jenkins build-command, deployment-command, backup-command, plugin-maintenance, and release-window exceptions after conversion.

Do not deploy as high or critical severity without correlation logic in the target SIEM.

Treat target-SIEM conversion, field mapping, host enrichment, exception logic, and correlation-layer promotion as required local deployment work.

DRI Assessment

Medium to high after conversion and Jenkins controller enrichment.

DRI

8.2 / 10

TCR Assessment

Good for portable endpoint detection. Stronger when joined with Jenkins audit, reverse-proxy, WAF, DNS, or proxy telemetry.

Operational TCR

7.8 / 10

Full-Telemetry TCR

8.9 / 10

Limitations

Legitimate Jenkins builds often execute shells, scripts, transfer tools, archive tools, and deployment utilities. Host scoping and approved job exceptions are required.

Detection Query Pattern

SIGMA rule requiring target-SIEM conversion and local exception enrichment:

title: Jenkins Controller Suspicious Service Context Execution

id: ENV-GENERATE-LOCAL-ID-JENKINS-CONTROLLER-SERVICE-EXECUTION

status: stable

description: Detects suspicious shell, scripting, transfer, archive, remote-access, or credential-related execution from Jenkins controller service context.

logsource:

  category: process_creation

detection:

  selection_parent_linux:

    ParentImage|contains:

      - '/jenkins'

      - '/java'

      - 'jenkins.war'

      - '/winstone'

  selection_parent_windows:

    ParentImage|contains:

      - '\jenkins'

      - '\java.exe'

      - 'jenkins.war'

      - '\wrapper.exe'

  selection_user:

    User|contains:

      - 'jenkins'

      - 'svc-jenkins'

      - 'ENV_JENKINS_SERVICE_USER'

  selection_process_linux:

    Image|endswith:

      - '/sh'

      - '/bash'

      - '/dash'

      - '/zsh'

      - '/python'

      - '/python3'

      - '/perl'

      - '/ruby'

      - '/groovy'

      - '/curl'

      - '/wget'

      - '/nc'

      - '/ncat'

      - '/socat'

      - '/ssh'

      - '/scp'

      - '/tar'

      - '/zip'

      - '/7z'

      - '/openssl'

  selection_process_windows:

    Image|endswith:

      - '\cmd.exe'

      - '\powershell.exe'

      - '\pwsh.exe'

      - '\certutil.exe'

      - '\bitsadmin.exe'

      - '\curl.exe'

      - '\wget.exe'

      - '\ssh.exe'

      - '\scp.exe'

      - '\tar.exe'

      - '\7z.exe'

  selection_suspicious_command:

    CommandLine|contains:

      - 'credentials.xml'

      - '/secrets/'

      - '\secrets\'

      - '/jobs/'

      - '\jobs\'

      - '/plugins/'

      - '\plugins\'

      - 'powershell -enc'

      - 'FromBase64String'

      - 'curl '

      - 'wget '

      - 'nc '

      - 'ncat '

      - 'bash -c'

      - '/bin/sh -c'

  condition: (selection_process_linux or selection_process_windows) and (selection_parent_linux or selection_parent_windows or selection_user) and selection_suspicious_command

fields:

  - Hostname

  - User

  - ParentImage

  - Image

  - CommandLine

  - CurrentDirectory

falsepositives:

  - Approved Jenkins build jobs

  - Approved deployment jobs

  - Approved backup jobs

  - Approved plugin maintenance

  - Approved administrative scripts

level: medium

YARA

Detection Viability Assessment

Limited but production-usable for artifact triage. YARA should not be treated as primary detection for Jenkins deserialization exploitation. It is viable for identifying suspicious Groovy, job configuration, plugin, shared-library, or workspace artifacts that may support persistence, credential access, process execution, or outbound staging after Jenkins controller compromise.

Rule

Jenkins Suspicious Groovy Credential Access or Process Execution Artifact

Rule Format

YARA artifact-scanning rule for Jenkins home, job configs, plugin directories, shared libraries, workspace artifacts, and forensic exports.

Detection Purpose

Detect suspicious Jenkins artifacts containing combinations of Jenkins Groovy access, credential-provider access, process execution, shell invocation, outbound transfer, or encoded payload behavior.

Detection Logic

Trigger when files under Jenkins home, job configuration exports, plugin directories, shared libraries, or suspicious workspace artifacts contain combinations of Jenkins object access, Groovy or Java process execution, credential-provider access, outbound network functions, shell invocation, or encoding behavior.

Assign medium severity for standalone matches.

Promote to high severity when the matched file is newly created, modified outside maintenance, associated with an unapproved job, unapproved plugin, unapproved shared library, suspicious workspace artifact, or correlated with suspicious Jenkins audit, web, endpoint, or egress telemetry.

Do not use this YARA rule as a standalone proof of compromise. Treat it as an artifact-triage accelerator that requires path, timestamp, owner, inventory, and telemetry correlation.

Required Telemetry

Jenkins home file exports.

Job configuration backups.

Plugin directory exports.

Shared-library repository content.

Workspace artifact exports.

File modification timestamps.

Approved Jenkins job inventory.

Approved Jenkins plugin inventory.

Approved Jenkins shared-library inventory.

Approved maintenance-window records.

Forensic collection workflow.

Engineering Implementation Instructions

Use this rule in controlled scanning workflows and forensic triage, not as primary live exploit detection.

Scan Jenkins home backups, job config exports, plugin directories, shared libraries, suspicious workspace artifacts, and forensic images.

Tune approved Groovy administration scripts, known shared libraries, plugin source paths, normal credential-helper code, and expected build tooling before alerting.

Correlate YARA hits with Jenkins audit logs, endpoint telemetry, job ownership, plugin inventory, shared-library ownership, change records, suspicious web activity, and file modification time.

Treat file collection, scanner integration, path scoping, approved-script exceptions, timestamp review, owner validation, and triage routing as required local deployment work.

DRI Assessment

Moderate for artifact review and persistence triage. Low for live runtime exploit detection.

DRI

7.0 / 10

TCR Assessment

Useful when matched artifacts are newly created, unapproved, or correlated with suspicious Jenkins behavior. Not sufficient as standalone proof of compromise.

Operational TCR

6.7 / 10

Full-Telemetry TCR

8.2 / 10

Limitations

YARA cannot reliably detect network exploitation or runtime deserialization without recoverable artifacts. Legitimate Jenkins administration and shared libraries may use Groovy, HTTP clients, credential providers, and process execution.

Detection Query Pattern

YARA artifact-scanning rule:

rule Jenkins_Suspicious_Groovy_Credential_Access_Or_Process_Execution_Artifact

{

    meta:

        description = "Detects suspicious Jenkins Groovy, job, plugin, or shared-library artifacts containing Jenkins credential access, process execution, shell invocation, or outbound staging behavior"

        author = "CyberDax"

        scope = "Jenkins home, job configs, plugins, shared libraries, workspace artifacts, forensic exports"

        severity = "medium"

    strings:

        $jenkins_1 = "Jenkins.instance" ascii wide

        $jenkins_2 = "hudson.model.Hudson.instance" ascii wide

        $jenkins_3 = "jenkins.model.Jenkins.getInstance" ascii wide

        $cred_1 = "com.cloudbees.plugins.credentials" ascii wide

        $cred_2 = "CredentialsProvider.lookupCredentials" ascii wide

        $cred_3 = "SystemCredentialsProvider" ascii wide

        $proc_1 = "ProcessBuilder" ascii wide

        $proc_2 = "getRuntime().exec" ascii wide

        $proc_3 = ".execute()" ascii wide

        $shell_1 = "/bin/bash" ascii wide

        $shell_2 = "/bin/sh" ascii wide

        $shell_3 = "cmd.exe" ascii wide

        $shell_4 = "powershell" ascii wide

        $net_1 = "new URL(" ascii wide

        $net_2 = "openConnection()" ascii wide

        $net_3 = "curl " ascii wide

        $net_4 = "wget " ascii wide

        $enc_1 = "Base64.decoder" ascii wide

        $enc_2 = "decodeBase64" ascii wide

        $enc_3 = "FromBase64String" ascii wide

    condition:

        filesize < 5MB and

        (

            (1 of ($jenkins_*) and 1 of ($cred_*) and 1 of ($proc_*)) or

            (1 of ($jenkins_*) and 1 of ($cred_*) and 1 of ($net_*)) or

            (1 of ($jenkins_*) and 1 of ($proc_*) and 1 of ($shell_*)) or

            (1 of ($proc_*) and 1 of ($shell_*) and 1 of ($net_*)) or

            (1 of ($enc_*) and 1 of ($proc_*) and 1 of ($shell_*))

        )

}

AWS

Detection Viability Assessment

Production-deployable only when Jenkins is hosted on AWS and AWS telemetry can be joined with Jenkins application-layer logs, endpoint telemetry, Jenkins controller asset mapping, and downstream cloud activity. AWS control-plane logs alone are not sufficient to detect Jenkins deserialization or controller-side behavior.

Rule

AWS Hosted Jenkins Config Abuse With Linked IAM Secret Registry or Deployment Activity

Rule Format

AWS Athena / CloudTrail / ALB / WAF / Route 53 / VPC Flow correlation pattern requiring Jenkins asset and identity mapping.

Detection Purpose

Detect AWS-hosted Jenkins controller configuration-path activity that aligns with unusual egress or Jenkins-linked IAM activity involving secrets, registry publication, infrastructure modification, Kubernetes deployment, or production-impacting actions.

Detection Logic

Trigger when an AWS-hosted Jenkins controller receives suspicious Jenkins configuration-path activity and the same controller private IP, instance ID, ECS task, EKS pod, Jenkins instance profile, Jenkins task role, or Jenkins-linked IAM principal performs rare egress or high-risk AWS API activity within 120 minutes.

Assign medium severity for rare egress from AWS-hosted Jenkins controllers.

Assign high severity when rare egress or high-risk IAM activity aligns with suspicious Jenkins configuration-path activity on a mapped Jenkins controller.

Promote to critical when Jenkins-linked identity performs Secrets Manager access, Parameter Store access, ECR image push, EKS deployment activity, IAM modification, CloudFormation update, S3 artifact manipulation, CodeDeploy action, or production infrastructure modification outside approved release windows.

Required Telemetry

AWS asset inventory.

EC2 tags.

ECS or EKS workload labels where applicable.

ALB access logs.

CloudFront logs where applicable.

AWS WAF logs.

VPC Flow Logs.

Route 53 Resolver query logs.

CloudTrail.

EDR telemetry from Jenkins controllers.

Jenkins audit logs.

Approved Jenkins IAM role lookup.

Approved Jenkins instance profile lookup.

Approved Jenkins release-window lookup.

Approved Jenkins egress-destination lookup.

Approved Jenkins controller asset lookup.

Engineering Implementation Instructions

Map Jenkins controllers to EC2 instance IDs, private IPs, ECS tasks, EKS pods, target groups, ALB targets, CloudFront distributions, WAF web ACLs, IAM roles, instance profiles, task roles, security groups, NAT gateways, and Route 53 Resolver sources.

Map Jenkins-linked IAM principals to Jenkins controller assets, jobs, deployment workflows, and production accounts wherever possible.

Validate that ALB, CloudFront, WAF, or reverse-proxy logs preserve Jenkins URI paths before enabling high severity.

Create lookups for approved Jenkins IAM roles, approved Jenkins instance profiles, approved release windows, approved deployment actions, approved egress destinations, approved production accounts, and approved Jenkins controller assets.

Do not attribute AWS-only anomalies to Jenkins compromise without Jenkins asset identity, Jenkins service account, IAM role, instance profile, job, or time-window correlation.

Treat AWS asset tagging, log-source joins, CloudTrail identity mapping, URI-log validation, endpoint correlation, identity-to-controller mapping, and release-window tuning as required local deployment work.

DRI Assessment

Moderate to high with ALB/WAF URI logs, Jenkins audit logs, EDR telemetry, Route 53 logs, VPC Flow Logs, asset mapping, and CloudTrail identity mapping.

DRI

8.0 / 10

TCR Assessment

Moderate operational confidence for AWS-only egress. High confidence when Jenkins web/audit activity joins to IAM secret, registry, infrastructure, or deployment activity linked to the affected controller.

Operational TCR

7.6 / 10

Full-Telemetry TCR

9.0 / 10

Limitations

VPC Flow Logs do not show URI paths or process context. CloudTrail does not show Jenkins local request handling. Production use requires application-layer and host telemetry. Critical severity requires a Jenkins-linked identity or controller-to-identity mapping, not time proximity alone.

Detection Query Pattern

AWS Athena / SQL-style correlation pattern requiring local table names and field validation:

WITH jenkins_controllers AS (

  SELECT

    controller_id,

    instance_id,

    private_ip,

    iam_role_arn,

    instance_profile_arn,

    account_id

  FROM ENV_AWS_JENKINS_CONTROLLERS

),

suspicious_jenkins_uri AS (

  SELECT

    from_unixtime(alb.time) AS event_time,

    alb.target_ip,

    alb.target_status_code,

    alb.client_ip,

    alb.request_verb,

    alb.request_url,

    alb.user_agent,

    jc.controller_id,

    jc.instance_id,

    jc.iam_role_arn,

    jc.instance_profile_arn,

    jc.account_id,

    'jenkins_config_submission' AS signal

  FROM ENV_AWS_ALB_ACCESS_LOGS alb

  JOIN jenkins_controllers jc

    ON alb.target_ip = jc.private_ip

  WHERE alb.request_verb = 'POST'

    AND (

      alb.request_url LIKE '%/config.xml%'

      OR alb.request_url LIKE '%/createItem%'

      OR alb.request_url LIKE '%/doCreateItem%'

      OR alb.request_url LIKE '%/doConfigSubmit%'

      OR alb.request_url LIKE '%/submitDescription%'

    )

    AND alb.client_ip NOT IN (SELECT source_ip FROM ENV_APPROVED_JENKINS_ADMIN_SOURCES)

    AND alb.client_ip NOT IN (SELECT source_ip FROM ENV_APPROVED_JENKINS_SCANNERS)

),

rare_egress AS (

  SELECT

    from_unixtime(v.start) AS event_time,

    v.srcaddr,

    v.dstaddr,

    v.dstport,

    v.action,

    jc.controller_id,

    jc.instance_id,

    'rare_jenkins_egress' AS signal

  FROM ENV_AWS_VPC_FLOW_LOGS v

  JOIN jenkins_controllers jc

    ON v.srcaddr = jc.private_ip

  WHERE v.action = 'ACCEPT'

    AND v.dstaddr NOT IN (SELECT ip FROM ENV_APPROVED_JENKINS_EGRESS_DESTINATIONS)

),

high_risk_cloudtrail AS (

  SELECT

    c.eventtime AS event_time,

    c.useridentity.arn AS principal_arn,

    c.eventname,

    c.eventsource,

    c.awsregion,

    c.sourceipaddress,

    jc.controller_id,

    jc.instance_id,

    'jenkins_linked_aws_activity' AS signal

  FROM ENV_AWS_CLOUDTRAIL c

  JOIN jenkins_controllers jc

    ON c.useridentity.arn = jc.iam_role_arn

    OR c.useridentity.arn = jc.instance_profile_arn

  WHERE c.eventname IN (

      'GetSecretValue',

      'PutSecretValue',

      'GetParameter',

      'GetParameters',

      'PutParameter',

      'UpdateFunctionCode',

      'CreateDeployment',

      'UpdateService',

      'RunTask',

      'PutImage',

      'BatchDeleteImage',

      'UpdateStack',

      'CreateStack',

      'DeleteStack',

      'CreateAccessKey',

      'AttachRolePolicy',

      'PutRolePolicy',

      'AssumeRole',

      'PutObject',

      'DeleteObject'

    )

    AND c.eventtime NOT BETWEEN ENV_APPROVED_RELEASE_WINDOW_START AND ENV_APPROVED_RELEASE_WINDOW_END

)

SELECT

  s.event_time AS uri_time,

  s.controller_id,

  s.instance_id,

  s.client_ip,

  s.request_url,

  s.user_agent,

  e.dstaddr,

  e.dstport,

  c.principal_arn,

  c.eventname,

  c.eventsource,

  c.awsregion

FROM suspicious_jenkins_uri s

LEFT JOIN rare_egress e

  ON s.controller_id = e.controller_id

 AND e.event_time BETWEEN s.event_time AND s.event_time + INTERVAL '120' MINUTE

LEFT JOIN high_risk_cloudtrail c

  ON s.controller_id = c.controller_id

 AND c.event_time BETWEEN s.event_time AND s.event_time + INTERVAL '120' MINUTE

WHERE e.signal IS NOT NULL OR c.signal IS NOT NULL

Azure

Detection Viability Assessment

Production-deployable only when Jenkins is hosted on Azure and Azure telemetry can be joined with Jenkins application-layer logs, endpoint telemetry, identity logs, and downstream deployment activity. Azure Activity Logs alone are not sufficient.

Rule

Azure Hosted Jenkins Config Abuse With Linked Identity Key Vault AKS or Registry Activity

Rule Format

Azure Monitor / Log Analytics KQL correlation pattern requiring Jenkins asset and identity mapping.

Detection Purpose

Detect Azure-hosted Jenkins controller configuration-path activity that aligns with rare egress or Jenkins-linked identity activity involving Key Vault, AKS, container registry, infrastructure modification, or production deployment.

Detection Logic

Trigger when an Azure-hosted Jenkins controller shows suspicious Jenkins configuration-path activity and the same controller, VM, workload, managed identity, service principal, or Jenkins-linked identity shows rare egress or high-risk Azure activity within 120 minutes.

Assign medium severity for rare egress from Azure-hosted Jenkins controllers.

Assign high severity when rare egress or high-risk Azure activity aligns with suspicious Jenkins configuration-path activity on a mapped Jenkins controller.

Promote to critical when Jenkins-linked identities access Key Vault secrets, modify AKS workloads, push container images, update production infrastructure, assign roles, or alter production resources outside approved release windows.

Required Telemetry

Application Gateway access logs.

Azure WAF logs.

Reverse-proxy logs where applicable.

Jenkins audit logs.

Defender for Endpoint telemetry from Jenkins controllers.

NSG Flow Logs.

Azure DNS or proxy logs.

Azure Activity Logs.

Microsoft Entra ID logs.

Key Vault audit logs.

AKS audit logs where applicable.

Azure Container Registry logs where applicable.

Approved Jenkins service principal lookup.

Approved Jenkins managed identity lookup.

Approved Jenkins release-window lookup.

Approved Jenkins egress-destination lookup.

Approved Jenkins controller asset lookup.

Engineering Implementation Instructions

Map Jenkins controllers to Azure VMs, VMSS instances, App Service instances, AKS workloads, private IPs, Application Gateway backend pools, WAF policies, managed identities, service principals, Key Vault access policies, container registries, and deployment targets.

Validate URI visibility in Application Gateway, WAF, reverse-proxy, or Jenkins access logs before enabling high severity.

Create approved Jenkins identity, release-window, egress-destination, resource-group, subscription, AKS cluster, Key Vault, container registry, and controller lookup tables.

Do not deploy an Azure Activity Log-only version of this rule.

Treat Azure asset mapping, identity mapping, WAF/Application Gateway field validation, endpoint telemetry joins, release-window tuning, identity-to-controller mapping, and SOC routing as required local deployment work.

DRI Assessment

Moderate with Azure-hosted Jenkins asset mapping and application-layer telemetry. Low for Azure-native control-plane-only telemetry.

DRI

7.6 / 10

TCR Assessment

Moderate operational confidence when Azure logs show suspicious downstream activity. High confidence requires Jenkins web/audit and endpoint correlation linked to the affected controller or Jenkins identity.

Operational TCR

7.3 / 10

Full-Telemetry TCR

8.8 / 10

Limitations

Azure Activity Logs do not show Jenkins request handling, Script Console use, or local process execution. Application-layer and endpoint telemetry are required for production confidence. Critical severity requires Jenkins-linked identity or controller-to-identity correlation, not time proximity alone.

Detection Query Pattern

Azure Monitor / Log Analytics KQL pattern requiring local table and field validation:

let JenkinsControllers =

    externaldata(ControllerId:string, PrivateIp:string, Hostname:string, BackendPool:string, ManagedIdentity:string, ServicePrincipal:string)

    ["ENV_AZURE_JENKINS_CONTROLLERS_LOOKUP"];

let ApprovedAdminSources =

    externaldata(SourceIp:string)

    ["ENV_APPROVED_JENKINS_ADMIN_SOURCES_LOOKUP"];

let ApprovedAdminSourceValues =

    ApprovedAdminSources

    | project SourceIp;

let ApprovedEgress =

    externaldata(DestinationIp:string, DestinationDomain:string)

    ["ENV_APPROVED_JENKINS_EGRESS_DESTINATIONS_LOOKUP"];

let ApprovedEgressValues =

    ApprovedEgress

    | project DestinationIp;

let SuspiciousJenkinsUri =

    AzureDiagnostics

    | where Category in ("ApplicationGatewayAccessLog","ApplicationGatewayFirewallLog")

    | where requestMethod_s == "POST"

    | where requestUri_s has_any ("/config.xml","/createItem","/doCreateItem","/doConfigSubmit","/submitDescription")

    | project

        UriTime=TimeGenerated,

        BackendPool=tostring(backendPoolName_s),

        SourceIp=tostring(clientIP_s),

        Uri=tostring(requestUri_s),

        Method=tostring(requestMethod_s),

        UserAgent=tostring(userAgent_s)

    | join kind=inner JenkinsControllers on BackendPool

    | where SourceIp !in (ApprovedAdminSourceValues);

let RareEgress =

    AzureNetworkAnalytics_CL

    | project

        EgressTime=TimeGenerated,

        PrivateIp=tostring(SrcIP_s),

        DestIP=tostring(DestIP_s),

        DestPort=tostring(DestPort_d),

        FlowStatus=tostring(FlowStatus_s)

    | join kind=inner JenkinsControllers on PrivateIp

    | where FlowStatus == "Allowed"

    | where DestIP !in (ApprovedEgressValues);

let HighRiskAzureActivity =

    AzureActivity

    | where OperationNameValue in (

        "MICROSOFT.KEYVAULT/VAULTS/SECRETS/READ",

        "MICROSOFT.KEYVAULT/VAULTS/SECRETS/WRITE",

        "MICROSOFT.CONTAINERSERVICE/MANAGEDCLUSTERS/WRITE",

        "MICROSOFT.CONTAINERREGISTRY/REGISTRIES/PUSH/WRITE",

        "MICROSOFT.RESOURCES/DEPLOYMENTS/WRITE",

        "MICROSOFT.COMPUTE/VIRTUALMACHINES/WRITE",

        "MICROSOFT.AUTHORIZATION/ROLEASSIGNMENTS/WRITE"

    )

    | project

        CloudTime=TimeGenerated,

        Identity=tostring(Caller),

        OperationNameValue=tostring(OperationNameValue),

        ResourceGroup=tostring(ResourceGroup),

        SubscriptionId=tostring(SubscriptionId)

    | join kind=inner JenkinsControllers on $left.Identity == $right.ServicePrincipal

    | where CloudTime !between (datetime(ENV_APPROVED_RELEASE_START) .. datetime(ENV_APPROVED_RELEASE_END));

SuspiciousJenkinsUri

| join kind=leftouter RareEgress on ControllerId

| where isempty(EgressTime) or (EgressTime between (UriTime .. UriTime + 120m))

| join kind=leftouter HighRiskAzureActivity on ControllerId

| where isempty(CloudTime) or (CloudTime between (UriTime .. UriTime + 120m))

| where isnotempty(DestIP) or isnotempty(OperationNameValue)

| project

    UriTime,

    ControllerId,

    Hostname,

    SourceIp,

    Uri,

    UserAgent,

    DestIP,

    DestPort,

    Identity,

    OperationNameValue,

    ResourceGroup,

    SubscriptionId

GCP

Detection Viability Assessment

Production-deployable only when Jenkins is hosted on GCP and GCP telemetry can be joined with Jenkins application-layer logs, endpoint telemetry, workload identity, and downstream deployment activity. GCP Audit Logs alone are not sufficient.

Rule

GCP Hosted Jenkins Config Abuse With Linked Service Account Secret Artifact or GKE Activity

Rule Format

BigQuery / Cloud Logging correlation pattern requiring Jenkins asset and identity mapping.

Detection Purpose

Detect GCP-hosted Jenkins controller configuration-path activity that aligns with rare egress or Jenkins-linked service-account activity involving Secret Manager, Artifact Registry, GKE, infrastructure modification, or production deployment.

Detection Logic

Trigger when a GCP-hosted Jenkins controller shows suspicious Jenkins configuration-path activity and the same VM, GKE workload, service account, or Jenkins-linked identity shows rare egress or high-risk GCP activity within 120 minutes.

Assign medium severity for rare egress from GCP-hosted Jenkins controllers.

Assign high severity when rare egress or high-risk GCP activity aligns with suspicious Jenkins configuration-path activity on a mapped Jenkins controller.

Promote to critical when Jenkins-linked service accounts access secrets, push artifacts, deploy to GKE, modify production infrastructure, assign IAM policy, or alter production resources outside approved release windows.

Required Telemetry

Cloud Load Balancing logs.

Cloud Armor logs where applicable.

Jenkins audit logs.

Compute Engine or GKE asset mapping.

Endpoint telemetry from Jenkins workloads.

VPC Flow Logs.

Cloud DNS logs.

Google Cloud Audit Logs.

Secret Manager audit logs.

GKE audit logs where applicable.

Artifact Registry logs where applicable.

Approved Jenkins service-account lookup.

Approved Jenkins release-window lookup.

Approved Jenkins egress-destination lookup.

Approved Jenkins controller asset lookup.

Engineering Implementation Instructions

Map Jenkins controllers to Compute Engine instances, GKE pods, namespaces, service accounts, private IPs, load-balancer backends, Cloud Armor policies, Artifact Registry repositories, Secret Manager secrets, deployment targets, and production projects.

Validate URI visibility through load balancer, ingress, reverse proxy, or Jenkins logs before enabling high-severity detections.

Create approved Jenkins service account, release-window, egress-destination, project, cluster, namespace, secret, registry, controller, and workload lookup tables.

Do not deploy a GCP Audit Log-only version of this rule.

Treat GCP asset mapping, workload identity mapping, URI-log validation, endpoint telemetry joins, release-window tuning, identity-to-controller mapping, and SOC routing as required local deployment work.

DRI Assessment

Moderate with GCP-hosted Jenkins asset mapping and application-layer telemetry. Low for GCP-native control-plane-only telemetry.

DRI

7.5 / 10

TCR Assessment

Moderate operational confidence when GCP logs show suspicious downstream activity. High confidence requires Jenkins web/audit and endpoint correlation linked to the affected controller or Jenkins service account.

Operational TCR

7.2 / 10

Full-Telemetry TCR

8.7 / 10

Limitations

GCP Audit Logs do not show Jenkins request handling, Script Console use, or local process execution. Application-layer and endpoint telemetry are required for production confidence. Critical severity requires Jenkins-linked service account or controller-to-identity correlation, not time proximity alone.

Detection Query Pattern

BigQuery / Cloud Logging SQL-style pattern requiring local table and field validation:

WITH jenkins_controllers AS (

  SELECT

    controller_id,

    backend_service_name,

    private_ip,

    instance_id,

    project_id,

    service_account_email

  FROM `ENV_GCP_JENKINS_CONTROLLERS`

),

suspicious_jenkins_uri AS (

  SELECT

    lb.timestamp AS event_time,

    lb.resource.labels.backend_service_name AS backend_service_name,

    lb.httpRequest.remoteIp AS source_ip,

    lb.httpRequest.requestMethod AS method,

    lb.httpRequest.requestUrl AS request_url,

    lb.httpRequest.userAgent AS user_agent,

    jc.controller_id,

    jc.private_ip,

    jc.service_account_email,

    jc.project_id

  FROM `ENV_GCP_HTTP_LOAD_BALANCER_LOGS` lb

  JOIN jenkins_controllers jc

    ON lb.resource.labels.backend_service_name = jc.backend_service_name

  WHERE lb.httpRequest.requestMethod = 'POST'

    AND (

      REGEXP_CONTAINS(lb.httpRequest.requestUrl, r'/config\.xml')

      OR REGEXP_CONTAINS(lb.httpRequest.requestUrl, r'/createItem')

      OR REGEXP_CONTAINS(lb.httpRequest.requestUrl, r'/doCreateItem')

      OR REGEXP_CONTAINS(lb.httpRequest.requestUrl, r'/doConfigSubmit')

      OR REGEXP_CONTAINS(lb.httpRequest.requestUrl, r'/submitDescription')

    )

    AND lb.httpRequest.remoteIp NOT IN (

      SELECT source_ip FROM `ENV_APPROVED_JENKINS_ADMIN_SOURCES`

    )

),

rare_egress AS (

  SELECT

    flow.timestamp AS event_time,

    flow.jsonPayload.connection.src_ip AS src_ip,

    flow.jsonPayload.connection.dest_ip AS dest_ip,

    flow.jsonPayload.connection.dest_port AS dest_port,

    flow.jsonPayload.disposition AS disposition,

    jc.controller_id

  FROM `ENV_GCP_VPC_FLOW_LOGS` flow

  JOIN jenkins_controllers jc

    ON flow.jsonPayload.connection.src_ip = jc.private_ip

  WHERE flow.jsonPayload.disposition = 'ALLOWED'

    AND flow.jsonPayload.connection.dest_ip NOT IN (

      SELECT dest_ip FROM `ENV_APPROVED_JENKINS_EGRESS_DESTINATIONS`

    )

),

high_risk_gcp_activity AS (

  SELECT

    audit.timestamp AS event_time,

    audit.protoPayload.authenticationInfo.principalEmail AS principal_email,

    audit.protoPayload.methodName AS method_name,

    audit.resource.labels.project_id AS project_id,

    audit.protoPayload.resourceName AS resource_name,

    jc.controller_id

  FROM `ENV_GCP_AUDIT_LOGS` audit

  JOIN jenkins_controllers jc

    ON audit.protoPayload.authenticationInfo.principalEmail = jc.service_account_email

  WHERE audit.protoPayload.methodName IN (

    'google.cloud.secretmanager.v1.SecretManagerService.AccessSecretVersion',

    'google.devtools.artifactregistry.v1.ArtifactRegistry.UploadAptArtifact',

    'google.devtools.artifactregistry.v1.ArtifactRegistry.UploadYumArtifact',

    'io.k8s.apps.v1.deployments.update',

    'io.k8s.core.v1.secrets.get',

    'v1.compute.instances.setMetadata',

    'v1.compute.instances.insert',

    'v1.compute.firewalls.patch',

    'SetIamPolicy'

  )

    AND audit.timestamp NOT BETWEEN TIMESTAMP('ENV_APPROVED_RELEASE_START') AND TIMESTAMP('ENV_APPROVED_RELEASE_END')

)

SELECT

  s.event_time,

  s.controller_id,

  s.source_ip,

  s.request_url,

  s.user_agent,

  e.dest_ip,

  e.dest_port,

  c.principal_email,

  c.method_name,

  c.project_id,

  c.resource_name

FROM suspicious_jenkins_uri s

LEFT JOIN rare_egress e

  ON s.controller_id = e.controller_id

 AND e.event_time BETWEEN s.event_time AND TIMESTAMP_ADD(s.event_time, INTERVAL 120 MINUTE)

LEFT JOIN high_risk_gcp_activity c

  ON s.controller_id = c.controller_id

 AND c.event_time BETWEEN s.event_time AND TIMESTAMP_ADD(s.event_time, INTERVAL 120 MINUTE)

WHERE e.dest_ip IS NOT NULL OR c.method_name IS NOT NULL

S26 Threat-to-Rule Traceability

Jenkins Configuration Submission Abuse

Covered by NDR / Network Behavioral Analytics, Splunk, Elastic, QRadar, AWS, Azure, and GCP where URI paths and controller identity are available.

User Impersonation or Privileged Jenkins Request Handling

Covered by Jenkins audit correlations, proxy user-context enrichment, crumb anomaly logic where available, Splunk and Elastic sequences, and QRadar building-block logic.

Script Console and Credential Activity

Covered by Splunk, Elastic, QRadar, SentinelOne, and endpoint/file correlations when privileged Jenkins activity aligns with suspicious configuration submission.

Job and Plugin Manipulation

Covered by Jenkins audit detections, Splunk, Elastic, QRadar, SentinelOne, SIGMA, and YARA artifact triage.

Controller-Side Execution and Sensitive File Access

Covered by SentinelOne, Splunk, Elastic, QRadar, SIGMA, and YARA where controller host or artifact telemetry is available.

Rare Controller Egress

Covered by NDR, DNS/proxy, Splunk, Elastic, AWS, Azure, and GCP correlations where Jenkins controller identity and egress telemetry are available.

Downstream CI/CD Abuse

Covered where source-code, artifact, cloud, Kubernetes, and deployment telemetry can be tied to Jenkins-linked users, service accounts, jobs, or release windows.

Evidence and Visibility Gaps

Covered by telemetry requirements, detection gaps, non-coverage conditions, and cloud telemetry limitations.

S29 Detection Coverage Summary

Coverage is strongest where Jenkins audit logs, URI-preserving web logs, endpoint process telemetry, endpoint file telemetry, DNS/proxy logs, artifact logs, cloud logs, Kubernetes logs, and release records can be joined by controller, user, job, identity, and time window.

Minimum viable coverage requires visibility into Jenkins configuration submission and privileged Jenkins activity.

Stronger coverage requires correlation across controller behavior and downstream CI/CD activity.

Cloud-native logs alone are insufficient unless combined with Jenkins application-layer logs, controller host telemetry, workload identity mapping, and deployment telemetry.

Customer-specific telemetry validation is expected and does not reduce production-readiness when Required Telemetry, Engineering Implementation Instructions, Limitations, and Notes / Next Suggested Steps provide the engineer or administrator with a clear implementation path.

S33 Defensive Control & Hardening Improvements

Upgrade affected Jenkins controllers to fixed versions.

Restrict Jenkins administrative and configuration endpoints.

Restrict network access to Jenkins controllers.

Require MFA for privileged Jenkins users.

Review Overall/Read permission assignments.

Review job, view, agent, and system configuration permissions.

Restrict Script Console access.

Maintain approved Jenkins administrator, job, plugin, service-account, maintenance-window, release-window, and egress inventories.

Log job configuration changes, plugin changes, credential activity, Script Console access, API token creation, node changes, user changes, and security realm changes.

Deploy endpoint telemetry and file integrity monitoring on Jenkins controllers.

Restrict outbound egress from Jenkins controllers to approved destinations where feasible.

Scope Jenkins cloud roles and Kubernetes service accounts narrowly.

Prefer short-lived credentials.

Validate artifact provenance and production deployments after suspicious Jenkins activity.

Preserve logs from Jenkins, WAF, reverse proxy, load balancer, endpoint, DNS, proxy, source-code, artifact, cloud, and Kubernetes sources during investigation.

S39 Economic Impact & Organizational Exposure

Jenkins controller deserialization and CI/CD control-plane abuse exposure creates organizational exposure by increasing uncertainty around Jenkins controller integrity, credential trust, job trust, plugin integrity, artifact provenance, source-code workflow integrity, cloud deployment authority, Kubernetes deployment authority, release governance, and production-change integrity. Exposure rises when affected Jenkins controllers support production releases, emergency fixes, artifact generation, infrastructure deployment, Kubernetes deployment, regulated workloads, or customer-facing applications.

The September 16, 2026 Jenkins security release expands the represented Jenkins plugin vulnerability surface across Script Security, Pipeline: Multibranch, Pipeline: Groovy Libraries, Gradle, GitLab, Warnings, Coverage, OWASP Dependency-Check, Robot Framework, Bitbucket Server Integration, Bitbucket Push and Pull Request, Gitee, and Keycloak Authentication. The release includes sandbox bypass, classpath approval bypass, classpath time-of-check/time-of-use behavior, System-scoped credential exposure, path traversal, credential-bearing server-side request forgery, credential-cache confusion, stored cross-site scripting, arbitrary controller-file creation or replacement with potential remote-code execution, OAuth token hijacking, webhook-driven credential capture, and post-authentication open redirect behavior.

The September 16 additions do not create a separate detection family or require replacement of the existing generic S25 rule families. Eleven vulnerabilities provide Direct Behavioral Coverage because their material Jenkins controller, credential, Script Security, filesystem, pipeline, or execution behavior aligns directly with the existing Jenkins-specific detection model. Nine require Coverage With Adaptation because reliable attribution depends on additional plugin-, browser-, OAuth-, webhook-, credential-scope-, API-, destination-, or identity-context localization.

The September 2, 2026 Jenkins security release materially expands the represented Jenkins vulnerability surface across Jenkins core and affected plugins. The release includes deserialization and unsafe object-instantiation behavior, stored cross-site scripting, CSRF-token exposure, configuration overwrite, agent takeover, session fixation, permission failures, build manipulation, Script Security weakening, server-side request forgery, controller-file read and write, controller remote-code execution, identity privilege escalation, agent command injection, plaintext-token exposure, and update-site content injection.

Affected Jenkins core versions generally include weekly 2.579 and earlier and LTS 2.568.2 and earlier except where the Jenkins advisory identifies a narrower affected range. CVE-2026-84649 applies to Jenkins weekly 2.447 through 2.579 and LTS 2.452.1 through 2.568.2. CVE-2026-84653 applies to Jenkins weekly 2.421 through 2.579 and LTS 2.426.1 through 2.568.2. Jenkins fixed the applicable core vulnerabilities in weekly 2.580 and LTS 2.568.3. Plugin-specific exposure depends on the affected plugin and version being installed. Parameterized Remote Trigger Plugin 3.2.2 and earlier had no fix available when the September 2 advisory was published.

The September 2 additions do not create a separate detection family or require an S21-S25 rewrite. Their durable behaviors map to the existing Jenkins and CI/CD control-plane model, including suspicious configuration submission, privileged Jenkins request handling, unusual authenticated-user or crumb activity, Script Console access, credential activity, job and plugin activity, controller execution, sensitive-file access, rare egress, artifact publication, cloud deployment activity, Kubernetes activity, and production-release activity. Product-, plugin-, browser-, identity-, or execution-context localization is required where the initiating vulnerability cannot be distinguished reliably through the existing Jenkins-specific telemetry alone.

Related exposure applies to TeamCity On-Premises versions before the fixed 2025.11.7 and 2026.1.3 releases, where an unauthenticated remote attacker with HTTP or HTTPS access can abuse the agent-polling protocol, bypass authentication checks, and execute arbitrary operating-system commands with the privileges of the TeamCity server process. CISA added CVE-2026-63077 to the Known Exploited Vulnerabilities Catalog on August 5, 2026, based on evidence of active exploitation.

The JetBrains Cadence incident provides confirmed real-world evidence that this TeamCity exploitation path can produce downstream credential, cloud, data, source-code, and software-development exposure. JetBrains confirmed that api.cadence.jetbrains.com was successfully exploited through CVE-2026-63077 during an affected period of August 8 through August 24, 2026. Confirmed impact includes extraction of Cadence-user personal data from the affected environment, compromise of a full 2024 Cadence server backup, compromise of multiple AWS IAM users and associated credentials or secrets contained in that backup, and access to files stored in S3 buckets within JetBrains AWS accounts used by Cadence. JetBrains also states that source code synchronized from PyCharm projects to the affected server may have been accessed.

JetBrains' September 3, 2026 final investigation update supersedes the earlier August 31 current-environment qualifier. JetBrains concluded that the threat actor obtained access that could have allowed them to reach storage used by the current Cadence environment containing data associated with current Cadence users, including email addresses, project source code, and credentials. JetBrains is treating the data stored there as potentially exposed. JetBrains did not identify additional affected users and states that the investigation has concluded. This finding establishes potential current-environment exposure but does not establish confirmed extraction of current project source code, current credentials, or every object stored in the current environment.

Related controller-trust exposure also applies to Red Hat Multicluster Engine for Kubernetes environments affected by CVE-2026-73266, where an authenticated tenant can manipulate ClusterClaim labels that are propagated by the clusterclaims-controller into ManagedCluster objects, enabling unauthorized cross-tenant ManagedClusterSet association and potential policy or workload injection into another tenant's clusters. Red Hat rates the vulnerability Important with a CVSS v3 base score of 7.1.

Related infrastructure-automation control-plane exposure also applies to Red Hat Ansible Automation Platform automation-controller deployments affected by the September 23, 2026 security cohort represented in this TTD. The 30 validated automation-controller vulnerabilities include cross-tenant authorization failures, controller-side command or code-execution paths, credential and secret exposure, server-side request forgery, stored cross-site scripting and session-impact paths, audit-source spoofing, workflow and job authorization bypass, information disclosure, and denial-of-service conditions. The existing CI/CD and infrastructure-automation behavior model remains applicable, but reliable attribution requires Ansible Automation Platform-specific user, organization, project, inventory, job-template, workflow, instance-group, execution-environment, credential, notification, receptor, controller-process, and Kubernetes or OpenShift context.

The September 23 Ansible Automation Platform additions do not create a separate detection family or require an S21-S25 rewrite. All 30 are Coverage With Adaptation because the durable controller, credential, workflow, execution, repository, cloud, Kubernetes, OpenShift, and downstream infrastructure behavior aligns to the existing TTD, while the initiating vulnerability cannot be attributed reliably without automation-controller-specific localization. Current authoritative evidence reviewed for this amendment does not establish CISA KEV status or confirmed in-the-wild exploitation for these 30 CVEs.

Estimated Economic Exposure

Estimated exposure should be scenario-based and tied to whether activity remains limited to suspicious configuration or affected-version exposure, becomes privileged Jenkins or TeamCity activity, results in unauthorized Red Hat Multicluster Engine cluster-association changes, or expands into credential theft, controller or agent execution, identity compromise, arbitrary file access, artifact manipulation, cloud or Kubernetes activity, production release compromise, cross-tenant policy or workload impact, customer-facing software impact, or rebuild of CI/CD or multicluster control-plane trust anchors.

The JetBrains Cadence incident demonstrates that TeamCity exploitation can progress beyond server-process execution into confirmed data exposure, credential compromise, cloud-resource access, potential source-code exposure, and broad downstream credential-rotation and assurance requirements without creating a separate detection family.

Low Impact Scenario

Estimated $25K - $150K.

This scenario applies when investigation confirms affected-version exposure or suspicious configuration-path activity without privileged Jenkins action, Script Console access, credential exposure, controller file read or write, job change, plugin change, controller or agent execution, session compromise, rare egress, artifact publication, cloud activity, Kubernetes activity, or production deployment impact.

For the September 2 Jenkins vulnerability set, this scenario applies where vulnerable Jenkins core or plugin versions are identified but available evidence establishes that the relevant deserialization, configuration manipulation, session or crumb abuse, agent takeover, unauthorized build action, security-control weakening, SSRF, sensitive-file access, identity privilege escalation, command execution, or token-access behavior did not occur.

For TeamCity, this scenario applies when the organization identifies an affected or previously affected server but can establish that exposure did not result in TeamCity server-process command execution, credential access, build or deployment modification, artifact activity, downstream integration abuse, or loss of CI/CD trust.

For CVE-2026-73266, this scenario applies when an affected Red Hat Multicluster Engine environment is identified but available audit evidence establishes that suspicious or unauthorized ClusterClaim activity did not result in unauthorized cross-tenant ManagedClusterSet association, policy distribution, workload injection, or loss of multicluster tenant-isolation trust.

For Ansible Automation Platform, this scenario applies when affected automation-controller versions or vulnerable component state are identified but available evidence establishes that unauthorized workflow or job activity, cross-tenant access, controller-side execution, credential or secret exposure, server-side requests, session abuse, Kubernetes or OpenShift service-account misuse, or downstream infrastructure changes did not occur.

Moderate Impact Scenario

Estimated $150K - $1.2M.

This scenario applies when confirmed or strongly suspected abuse affects one or more production Jenkins controllers and the organization cannot quickly rule out user impersonation, session abuse, credential exposure, agent takeover, job modification, plugin modification, sensitive-file access, artifact activity, cloud activity, Kubernetes activity, or release-path abuse.

For the September 2 Jenkins vulnerability set, this scenario also applies where suspicious behavior creates uncertainty around configuration integrity, Jenkins authentication or authorization state, build integrity, agent integrity, shared-library state, Jenkins-originated outbound connections, controller filesystem state, plugin configuration, exposed credential identifiers, or remote-trigger tokens, but the organization can still bound the affected controller, identities, agents, jobs, plugins, credentials, and downstream systems.

For TeamCity, this scenario also applies when suspected or confirmed agent-polling protocol abuse creates uncertainty around TeamCity server-process command execution, access to controller data or credentials, or modification of TeamCity-controlled build and deployment workflows. CISA KEV confirmation and JetBrains' subsequent reporting of active and attempted exploitation increase the need to investigate whether exposed TeamCity servers were compromised before the applicable fix or security patch plugin was applied.

For CVE-2026-73266, this scenario also applies when suspicious or confirmed ClusterClaim manipulation creates uncertainty around whether a tenant caused unauthorized ManagedCluster metadata changes, cross-tenant ManagedClusterSet association, or subsequent policy or workload distribution, but the organization can still bound the affected clusters and has no evidence of broader tenant or multicluster control-plane impact.

For Ansible Automation Platform, this scenario also applies when suspicious or confirmed automation-controller activity creates uncertainty around project or inventory integrity, workflow or job authorization, credential use, instance-group or execution-environment activity, notification or external-integration behavior, controller process execution, receptor identity, or Kubernetes or OpenShift activity, but the organization can still bound the affected controller, identities, credentials, jobs, projects, integrations, and downstream systems.

High Impact Scenario

Estimated $1M - $8M+.

This scenario applies when abuse involves Script Console execution, arbitrary controller file read or write, controller remote-code execution, agent takeover, identity privilege escalation, credential theft, malicious job modification, plugin persistence, security-control weakening, unauthorized artifact publication, source-code abuse, cloud control-plane activity, Kubernetes deployment manipulation, production release compromise, public disclosure, customer-facing software impact, or durable CI/CD access.

The September 16 Jenkins vulnerability set includes paths capable of reaching this scenario through Script Security sandbox bypass and controller-JVM code execution, arbitrary Jenkins-controller file creation or replacement with potential remote-code execution, System-scoped credential exposure, controller-file path traversal, or theft of credentials or OAuth tokens used by downstream integrations. Presence of a vulnerable plugin does not establish that these outcomes occurred; the high-impact model applies only when exploitation or sufficiently corroborated consequential behavior is established.

The September 2 Jenkins vulnerability set contains multiple paths capable of reaching this scenario, including Script Console-backed remote-code execution, controller-side arbitrary-code execution, controller-file writes capable of leading to remote code execution, authentication as arbitrary Jenkins users, takeover of Jenkins agents, Entra-backed Jenkins privilege escalation, and operating-system command execution on build agents.

Presence of one of those vulnerabilities does not by itself establish a high-impact incident. The higher exposure model applies only when exploitation or sufficiently corroborated post-exploitation behavior establishes material compromise of controller, agent, identity, credential, artifact, source-code, deployment, cloud, Kubernetes, or production-release trust.

For TeamCity, this scenario also applies when confirmed exploitation results in TeamCity server-process command execution followed by credential theft, malicious build or deployment modification, artifact compromise, repository abuse, cloud or Kubernetes access, production change, persistent CI/CD access, or inability to establish the integrity of software-delivery outputs.

The JetBrains Cadence incident is a confirmed high-impact TeamCity exploitation case because exploitation of CVE-2026-63077 resulted in unauthorized access to the affected Cadence environment, extraction of personal data, compromise of a historical full-server backup, compromise of AWS IAM users and associated credentials or secrets, access to JetBrains S3-hosted data, potential synchronized-source-code exposure, and a requirement to treat broad classes of credentials and secrets made available to the affected service as compromised.

The Cadence incident does not establish that every exploited TeamCity environment will experience equivalent downstream effects. JetBrains' September 3 final investigation update establishes potential exposure of current Cadence storage containing current-user email addresses, project source code, and credentials, but it does not establish confirmed extraction of those current-environment data classes.

For CVE-2026-73266, this scenario also applies when confirmed cross-tenant ManagedClusterSet manipulation results in unauthorized policy or workload injection into victim clusters, materially affects another tenant's managed resources, or prevents the organization from establishing the integrity of multicluster membership, governance, policy distribution, workload state, or tenant isolation.

For Ansible Automation Platform, this scenario also applies when confirmed automation-controller exploitation results in controller-side command or code execution, credential or secret theft, cross-tenant control-plane access, unauthorized workflow or job execution, compromised project synchronization, service-account or namespace-secret exposure, malicious Kubernetes or OpenShift execution, downstream infrastructure modification, or inability to establish the integrity of automation-controlled systems.

Annualized Risk Exposure

Estimated $150K - $1.2M+ for materially exposed Jenkins environments with affected controller or plugin versions, privileged configuration permissions, production release workflows, incomplete logging, missing endpoint telemetry, broad Jenkins-managed credentials, weak egress visibility, incomplete artifact provenance, or incomplete downstream identity mapping.

Exposure may exceed $1M - $8M+ where Jenkins or TeamCity abuse results in credential theft, identity privilege escalation, controller or agent execution, artifact manipulation, production deployment impact, customer-facing software impact, legal review, customer communications, or board-level reporting, or where Red Hat Multicluster Engine controller abuse results in material cross-tenant policy, workload, governance, or cluster-management impact.

The Cadence incident reinforces the upper exposure model because one unpatched TeamCity-dependent service required investigation of personal-data exposure, historical backup compromise, cloud credentials, cloud storage, possible source-code exposure, connected external-service credentials, customer or user notification, and regulatory-response obligations.

Exposure may also increase materially where Ansible Automation Platform automation-controller compromise affects privileged infrastructure automation, cloud or Kubernetes administration, production deployment workflows, credential brokering, or multi-environment orchestration and the organization cannot quickly re-establish controller, credential, workflow, and downstream infrastructure trust.

Operational Dependency

Operational dependency is high where Jenkins or TeamCity supports production releases, engineering delivery, emergency fixes, artifact generation, infrastructure deployment, cloud automation, Kubernetes deployment, source-code integration, credential brokering, or regulated software-delivery workflows.

The September 16 Jenkins advisory adds dependency concern where affected plugins participate in sandboxed Pipeline execution, shared libraries, multibranch credential resolution, source-control integrations, build tooling, report processing, webhook processing, OAuth flows, or authentication. Multiple affected plugins may coexist on one Jenkins controller and create separate paths into the same software-delivery trust boundary.

The September 2 Jenkins advisory increases dependency concern where affected plugins participate in authentication, build execution, shared libraries, source-code integration, backup, report handling, credential use, remote triggering, identity federation, or other Jenkins control-plane functions. Multiple affected components may coexist on one Jenkins controller and can therefore create separate paths into the same software-delivery trust boundary.

The Cadence incident demonstrates additional dependency risk where TeamCity orchestrates cloud-hosted developer workloads and has access to execution inputs and outputs, cloud credentials, source code, package or container registries, deployment credentials, and other external systems used by development workflows.

Operational dependency is also high where Red Hat Multicluster Engine provides centralized management, tenant separation, ManagedClusterSet governance, policy distribution, or workload coordination across multiple Kubernetes or OpenShift clusters.

Operational dependency is also high where Red Hat Ansible Automation Platform provides centralized infrastructure automation, configuration management, cloud automation, Kubernetes or OpenShift execution, credential brokering, project synchronization, workflow orchestration, or production deployment authority.

Control Trust

Control trust is reduced when the organization cannot prove that Jenkins users, permissions, sessions, configuration submissions, job changes, plugin changes, Script Console activity, credential access, controller file reads or writes, agent changes, service-account execution, artifact publication, cloud activity, Kubernetes activity, and deployment records remained legitimate.

The September 16 Jenkins vulnerability set expands relevant trust objects to include Script Security sandbox enforcement and approved classpaths, Pipeline credential-resolution context, shared-library paths, configured integration credentials, attacker-influenced outbound destinations, report and build-result identifiers, Robot Framework archive paths, Bitbucket OAuth callback state, webhook-supplied destination data, Gitee build-cause content, and Keycloak post-authentication redirect targets.

The September 2 Jenkins vulnerability set increases the number of trust objects that may require validation. Relevant objects include Jenkins configuration XML, configuration-bound objects, users and sessions, CSRF crumbs, agents and inbound-agent secrets, build parameters, build state, Script Security settings, shared-library caches, plugin global configuration, Jenkins-originated outbound requests, configuration-history storage, backup destinations, SAML metadata, controller files, Entra-backed authorization mappings, build-agent commands, Jenkins credential identifiers, remote-trigger tokens, and self-hosted update-site metadata.

For TeamCity, control trust is reduced when the organization cannot prove that server-process and child-process execution, users, tokens, projects, build configurations, agents, plugins, artifacts, repositories, connected integrations, cloud activity, Kubernetes activity, and deployment workflows remained legitimate during the potential exploitation window.

For Cadence-aligned TeamCity exploitation, control trust is further reduced when an organization cannot establish whether credentials or secrets accessible to TeamCity-managed workloads were exposed or reused, whether synchronized source code was accessed, whether connected cloud or storage resources were reached, whether package or container registries were modified, or whether deployment or signing credentials remained trustworthy.

For CVE-2026-73266, control trust is reduced when the organization cannot prove that ClusterClaim creation, update, patch, or label activity; clusterclaims-controller reconciliation; ManagedCluster metadata changes; ManagedClusterSet membership; policy distribution; workload deployment; and originating tenant or service-account activity remained authorized and tenant-consistent.

For Ansible Automation Platform, control trust is reduced when the organization cannot prove that automation-controller users, teams, organizations, projects, inventories, credentials, job templates, workflow job templates, schedules, notifications, execution environments, instance groups, container groups, receptor connections, controller web and task processes, project synchronization, and downstream Kubernetes or OpenShift activity remained authorized and tenant-consistent.

Visibility Confidence

Visibility confidence is highest when Jenkins audit logs, web logs, endpoint telemetry, file telemetry, DNS or proxy logs, source-code records, artifact records, cloud logs, Kubernetes logs, release records, approved inventories, plugin inventories, agent state, identity records, and change-control records can be joined reliably.

For the September 16 Jenkins vulnerabilities, additional useful evidence includes:

·        Jenkins plugin inventory and affected-version state.

·        Script Security sandboxed Pipeline or Groovy execution context.

·        Script Security approval and classpath-approval records where retained.

·        Controller-side process or execution activity associated with sandboxed scripts.

·        Approved classpath JAR inventory, source URL, and retrieval context.

·        REST API or CLI item-copy and configuration activity involving Script Security classpaths.

·        Pipeline: Multibranch resolveScm use and System-scoped credential access.

·        Pipeline: Groovy Libraries configured library paths, symbolic-link state, SCM checkout boundaries, and controller-file activity.

·        Gradle build-scan URLs, configured Develocity server state, outbound destinations, and Develocity access-key use.

·        GitLab credential identifiers, folder scope, API-client cache state, and resulting GitLab activity.

·        Warnings and Coverage result identifiers, REST-submitted job configuration, rendered-page context, and Content Security Policy state.

·        OWASP Dependency-Check report provenance, CWE content, rendered-page context, and browser activity.

·        Robot Framework archive-directory configuration and resulting controller-file creation or replacement.

·        Bitbucket Server Integration OAuth request-token, callback, redirect, token, and verifier context.

·        Bitbucket Push and Pull Request webhook payload URLs, configured Bitbucket endpoint, Jenkins-originated network activity, and credential use.

·        Gitee webhook sender data, build-cause rendering, and browser activity.

·        Keycloak Authentication login activity and post-authentication redirect targets.

For the September 2 Jenkins vulnerabilities, additional useful evidence includes:

·        Jenkins core and plugin version inventory.

·        Configuration submissions and configuration-history records.

·        Script Console access and controller-side process execution.

·        Jenkins user, session, and remember-me activity.

·        CSRF crumb use where available.

·        Agent configuration changes and inbound-agent secret access.

·        Build-parameter access and unexpected build cancellation.

·        Script Security approval and sandbox-setting changes.

·        Pipeline shared-library-cache deletion.

·        Jenkins-originated connections to unexpected LDAP, GitLab, or other destinations.

·        Job Configuration History and ThinBackup path changes.

·        SAML metadata changes and resulting Jenkins authentication.

·        Controller filesystem reads or writes associated with affected plugins.

·        Entra group object-ID and display-name changes correlated with Jenkins authorization.

·        Build environment variables and command-line execution on Jenkins agents.

·        Access to Jenkins credential identifiers or remote-trigger tokens.

·        Self-hosted update-site plugin metadata and rendered-page activity where applicable.

TeamCity visibility additionally depends on TeamCity application and reverse-proxy logs, TeamCity server-process and child-process telemetry, and records for users, tokens, projects, build configurations, agents, plugins, artifacts, and connected integrations. Incomplete TeamCity telemetry may prevent confirmation of the initial protocol abuse or its downstream effects.

The Cadence incident demonstrates the need to extend TeamCity compromise assessment into connected environments. Relevant evidence may include:

·        Cloud IAM authentication and administrative activity.

·        S3 or equivalent cloud-storage object access.

·        Unexpected repository clones or downloads.

·        Unexpected repository commits.

·        Changes to repository secrets, webhooks, collaborators, or permissions.

·        New or modified personal-access tokens, API tokens, or SSH keys.

·        New service accounts created in external services.

·        Unexpected cloud IAM role, policy, or permission changes.

·        Unexpected cloud-storage access.

·        Unexpected publication or modification of packages or releases.

·        Package-registry or container-registry activity.

·        Deployment activity occurring after suspected TeamCity compromise.

·        Use of credentials previously stored in or accessible through the affected CI/CD service.

Absence of one published Cadence indicator should not be treated as proof that a related environment was unaffected. JetBrains states that its published Cadence indicators are not exhaustive. Investigation should remain behavior-led and correlated across TeamCity, endpoint, identity, repository, registry, cloud, storage, deployment, and network telemetry.

Red Hat Multicluster Engine visibility additionally depends on Kubernetes or OpenShift audit logs, originating tenant and service-account identity, ClusterClaim create/update/patch records, metadata and label changes, clusterclaims-controller activity, ManagedCluster state history, ManagedClusterSet membership changes, admission decisions, policy-distribution records, and downstream workload-deployment activity. Incomplete identity or controller-correlation telemetry may prevent confirmation that a lower-trust tenant action caused the resulting privileged multicluster state change.

Ansible Automation Platform visibility additionally depends on automation-controller audit and application records; user, team, organization, project, inventory, job, workflow, schedule, credential, notification, execution-environment, and instance-group records; controller web and task process telemetry; receptor identity and connection state; source-control synchronization history; and Kubernetes or OpenShift audit records where container groups or cluster-backed execution are used. Incomplete identity, authorization, credential, process, project-synchronization, receptor, or cluster telemetry may prevent reliable attribution of the initiating vulnerability or its downstream effects.

Change-Control Confidence

Change-control confidence is high when Jenkins upgrades, plugin updates, job changes, plugin changes, credential changes, Script Console use, agent changes, identity-provider configuration, release workflows, deployment jobs, cloud changes, Kubernetes changes, and emergency remediation are documented and attributable.

For the September 16 Jenkins release, applicable affected plugins should be upgraded to the fixed release identified by Jenkins.

·        Bitbucket Push and Pull Request Plugin should be upgraded to 4.1.0 or later.

·        Bitbucket Server Integration Plugin should be upgraded to 6.0.2 or later.

·        Coverage Plugin should be upgraded to 3.3361.v0626103a_67e6 or later.

·        Gitee Plugin should be upgraded to 1304.v2702f1d71cde or later.

·        GitLab Plugin should be upgraded to 1.2152.veec0897048b_0 or later.

·        Gradle Plugin should be upgraded to 2.20.1253.vc116f0763a_eb_ or later.

·        Keycloak Authentication Plugin should be upgraded to 2.4.2 or later.

·        OWASP Dependency-Check Plugin should be upgraded to 5.6.5 or later.

·        Pipeline: Groovy Libraries Plugin should be upgraded to 806.v408277b_33d1d or later.

·        Pipeline: Multibranch Plugin should be upgraded to 842.v3a_b_59b_57b_e6e or later.

·        Robot Framework Plugin should be upgraded to 6.3.0 or later.

·        Script Security Plugin should be upgraded to 1422.v06869826dd9b_ or later.

·        Warnings Plugin should be upgraded to 13.10259.v80f407cb_03a_e or later.

For the September 2 Jenkins release, Jenkins weekly should be upgraded to 2.580 or later and Jenkins LTS should be upgraded to 2.568.3 or later where affected. Applicable affected plugins should be upgraded to the fixed release identified by Jenkins.

·        Allure Plugin should be upgraded to 2.36.0 or later.

·        Customizable Header Plugin should be upgraded to 330.v8a_8d87511ea_1 or later.

·        File Parameter Plugin should be upgraded to 433.va_0b_80359d54d or later.

·        GitLab Plugin should be upgraded to 1.9.182144.vc1c369226a_52 or later.

·        Job Configuration History Plugin should be upgraded to 1380.v762185b_9a_793 or later.

·        LDAP Plugin should be upgraded to 825.v2fca_37dd5b_cb_ or later.

·        Microsoft Entra ID Plugin should be upgraded to 711.v34046f788fd7 or later.

·        Performance Plugin should be upgraded to 1017.v9e9f7b_b_b_c5e7 or later.

·        Pipeline: Build Step Plugin should be upgraded to 601.v6d4c6d1a_9dc7 or later.

·        Pipeline: Groovy Libraries Plugin should be upgraded to 805.va_fc79344957d or later.

·        SAML Plugin should be upgraded to 4.623.v7875d61cd9f5 or later.

·        Script Security Plugin should be upgraded to 1415.v9a_f9b_3a_c253d or later.

·        SonarQube Scanner Plugin should be upgraded to 2.19.0 or later.

·        ThinBackup Plugin should be upgraded to 2.1.5 or later.

·        TICS Plugin should be upgraded to 2026.1.0 or later.

·        XebiaLabs XL Deploy Plugin should be upgraded to 26.3.0 or later.

·        update-center2 should be upgraded to 3.18.4 or later where organizations operate affected self-hosted Jenkins update sites.

·        Parameterized Remote Trigger Plugin 3.2.2 and earlier had no fix available at advisory publication. Organizations using affected releases should restrict access to affected job configuration, protect and rotate exposed remote-trigger tokens where required, and apply a fixed release when one becomes available.

For TeamCity, change-control confidence additionally depends on documented upgrades to 2025.11.7, 2026.1.3, or a later fixed version; verified installation of the applicable security patch plugin where immediate upgrade was not possible; and attributable changes to projects, build configurations, agents, plugins, credentials, artifacts, and connected deployment workflows.

The Cadence incident demonstrates the consequence of incomplete remediation execution. JetBrains states that the affected Cadence server should have been patched as part of its response to CVE-2026-63077 but was not. Change-control assurance should therefore verify not only that remediation was approved or scheduled, but that the affected TeamCity server actually received a fixed release or the applicable security patch plugin and that post-remediation compromise assessment was completed.

For Red Hat Multicluster Engine, change-control confidence additionally depends on attributable ClusterClaim modifications, ManagedCluster metadata changes, ManagedClusterSet membership changes, tenant-permission changes, policy-distribution changes, workload-deployment activity, controller updates, and remediation actions affecting the clusterclaims-controller or related multicluster governance controls.

For Red Hat Ansible Automation Platform, change-control confidence additionally depends on documented automation-controller remediation, attributable changes to users, teams, organizations, projects, inventories, credentials, job templates, workflow job templates, execution environments, instance groups, container groups, notifications, receptor configuration, project synchronization, and downstream Kubernetes or OpenShift resources. Applicable affected automation-controller packages should be updated to the fixed releases identified by Red Hat for the installed Ansible Automation Platform stream.

Downstream Dependency

Downstream dependency is high when Jenkins or TeamCity connects to source-code repositories, artifact repositories, package registries, container registries, cloud platforms, Kubernetes clusters, secrets managers, identity providers, deployment tools, infrastructure-as-code systems, or customer-facing applications.

The September 16 Jenkins vulnerability set adds downstream concern where affected components can expose System-scoped or integration credentials, cause Jenkins to connect to attacker-controlled destinations with configured credentials, redirect OAuth material, modify or access Jenkins controller files, or escape Script Security controls and execute code in the controller JVM.

The September 2 Jenkins vulnerability set adds downstream concern where affected components expose Jenkins sessions, agent secrets, build parameters, configured API tokens, controller files, Jenkins credential identifiers, remote-trigger tokens, or privileged identity mappings, or where controller or agent execution can reach connected software-delivery systems.

The Cadence incident confirms that downstream exposure can include cloud IAM credentials, cloud-storage objects, synchronized source code, source-control credentials and tokens, package-registry credentials, container-registry credentials, API tokens, webhooks, SSH or deployment keys, service-account credentials, signing keys or certificates, and credentials for other external systems made available to TeamCity-orchestrated workloads.

Downstream dependency is also high where Red Hat Multicluster Engine manages clusters supporting production workloads, regulated environments, shared infrastructure, tenant-specific applications, centralized policy enforcement, secrets-dependent workloads, or other business-critical Kubernetes or OpenShift services.

Downstream dependency is also high where Ansible Automation Platform controls servers, cloud resources, network devices, Kubernetes or OpenShift clusters, secrets-dependent workloads, source-control projects, deployment workflows, or other business-critical infrastructure through automation-controller credentials and execution authority.

Customer and Regulatory Exposure

Customer and regulatory exposure increases when suspicious Jenkins or TeamCity activity may affect customer-facing software, regulated workloads, artifact integrity, deployment integrity, credential confidentiality, source-code integrity, production change history, identity integrity, or customer-delivered packages and images.

The September 16 Jenkins vulnerabilities may increase customer and regulatory exposure where exploitation results in arbitrary controller execution, controller-file manipulation, credential or OAuth-token exposure, unauthorized downstream integration access, or inability to establish software-delivery and release integrity.

The September 2 Jenkins vulnerabilities may increase customer and regulatory exposure where exploitation results in unauthorized identity access, exposure of controller-hosted data or credentials, compromise of Jenkins agents, arbitrary controller execution, altered software-delivery workflows, or inability to establish artifact and production-release integrity.

The Cadence incident confirms that TeamCity exploitation can also create direct personal-data exposure. JetBrains confirmed extraction from the affected environment of Cadence-user data including usernames, real names, email addresses, last-login timestamps, and last-accessed IP addresses. Exposure of this information may increase phishing, social-engineering, impersonation, privacy, customer- or user-notification, and regulatory-response requirements in addition to the software-delivery and credential-assurance burden.

Customer and regulatory exposure also increases when unauthorized Red Hat Multicluster Engine activity may cause cross-tenant access, policy application, workload deployment, confidentiality impact, or uncertainty over whether another tenant's managed Kubernetes or OpenShift resources remained isolated and trustworthy.

Customer and regulatory exposure may also increase where unauthorized Ansible Automation Platform activity affects regulated infrastructure, production systems, customer-facing services, privileged credentials, deployment integrity, tenant separation, or the organization's ability to establish that automation-controlled changes remained authorized.

Residual Economic Risk

Residual economic risk remains if the organization cannot prove that affected Jenkins controllers and plugins were upgraded, permissions were validated, credentials and exposed tokens were rotated where required, job and plugin integrity were reviewed, controller filesystem changes were scoped, agent integrity was validated, authentication and authorization state remained trustworthy, artifacts were validated, cloud and Kubernetes activity was reviewed, production deployments were verified, and CI/CD trust was restored.

For the September 16 Jenkins vulnerabilities, residual risk remains where organizations cannot determine whether Script Security sandbox or classpath protections were bypassed, System-scoped credentials were accessed, Pipeline library paths reached unintended controller locations, Jenkins sent protected integration credentials to attacker-controlled destinations, controller files were created or replaced through Robot Framework paths, OAuth token material was redirected, or malicious webhook or report content was rendered before remediation.

For the September 2 Jenkins vulnerabilities, residual risk remains where organizations cannot determine whether the affected core or plugin functionality was exercised before remediation, whether suspicious configuration submission occurred, whether Jenkins sessions or crumbs were abused, whether agents were overwritten or compromised, whether protected build or credential information was accessed, whether Jenkins security controls were weakened, whether Jenkins initiated attacker-directed network connections, whether controller files were read or written, whether identity-provider configuration or authorization mappings were altered, whether build-agent commands were manipulated, or whether remote-trigger tokens were exposed.

For CVE-2026-84676 specifically, residual risk remains while affected Parameterized Remote Trigger Plugin releases remain in use without a vendor fix and organizations cannot establish whether plaintext tokens stored in job config.xml were accessible to unauthorized users or through controller filesystem access.

For TeamCity, residual risk remains where affected servers were not upgraded to 2025.11.7, 2026.1.3, or a later fixed version or protected with the applicable security patch plugin; potential pre-remediation compromise was not investigated; server-process and child-process activity was not reviewed; credentials were not assessed or rotated where exposure was possible; or TeamCity-controlled projects, builds, agents, plugins, artifacts, repositories, cloud environments, Kubernetes environments, and production-deployment workflows could not be validated.

The Cadence incident reinforces that remediation cannot stop with TeamCity patching. Residual risk remains until potentially exposed credentials and secrets are rotated or otherwise invalidated, connected cloud and storage activity is reviewed, repositories and synchronized source code are assessed, package and container registries are checked for unauthorized modification, deployment and signing authority is validated, and pre-remediation activity is reconciled.

JetBrains' September 3 final investigation update supersedes the earlier August 31 current-environment qualifier for residual-risk assessment. The threat actor obtained access that could have allowed access to current Cadence storage containing current-user email addresses, project source code, and credentials, and JetBrains is treating that data as potentially exposed. This does not establish confirmed extraction of current project source code or current credentials, but the potentially exposed storage must remain within credential, source-code, and connected-system assurance scope.

For CVE-2026-73266, residual risk remains where affected Multicluster Engine environments cannot establish whether tenant-controlled ClusterClaim changes were legitimate, whether arbitrary labels propagated into ManagedCluster objects, whether unauthorized ManagedClusterSet associations occurred, whether policy or workload injection affected another tenant's clusters, or whether tenant isolation and multicluster governance were restored. Red Hat states that mitigation is either unavailable or currently available options do not meet its Product Security mitigation criteria.

For Ansible Automation Platform, residual risk remains where affected automation-controller components were not remediated; controller, identity, authorization, credential, project, workflow, and execution state cannot be reconciled; potentially exposed credentials or secrets were not assessed or rotated where required; controller web or task process activity was not reviewed; project synchronization and external integrations were not validated; or downstream cloud, Kubernetes, OpenShift, or infrastructure changes cannot be attributed confidently.

Proof-of-Concept Behavioral Coverage Assessment

This TTD's behavioral model covers Jenkins controller abuse aligned with configuration submission, privileged request handling, unusual authenticated-user or crumb activity, Script Console access, arbitrary file read, credential access, job manipulation, plugin manipulation, controller execution, rare egress, artifact publication, source-code activity, cloud activity, Kubernetes deployment activity, and production release manipulation.

The model provides Direct Behavioral Coverage for CVE-2026-53435 where exploitation produces observable Jenkins controller behavior aligned with the TTD's S21 through S25 detection strategy.

The September 16 Jenkins advisory adds 11 vulnerabilities assessed as Direct Behavioral Coverage because the material behavior or resulting Jenkins activity aligns directly with the existing Jenkins-specific detection model.

·        CVE-2026-92137 — Direct Behavioral Coverage — Robot Framework Plugin path traversal permits attackers with Item/Configure permission to create or replace arbitrary files on the Jenkins controller with attacker-specified content and can lead to remote code execution. This aligns directly with controller-file modification and controller execution.

·        CVE-2026-92131 — Direct Behavioral Coverage — Pipeline: Groovy Libraries Plugin fails to restrict a configured library path to the SCM checkout and follows symbolic links outside that checkout, allowing configured Pipelines to read files in resources directories and delete files in test directories on the Jenkins controller. This aligns directly with shared-library manipulation and controller-file activity.

·        CVE-2026-92130 — Direct Behavioral Coverage — Pipeline: Multibranch Plugin permits the resolveScm Pipeline step to use System-scoped credentials reserved for global configuration, enabling attackers with Item/Configure permission to access and capture credentials they are not entitled to use. This aligns directly with Jenkins credential activity and privileged Pipeline behavior.

·        CVE-2026-92129 — Direct Behavioral Coverage — Script Security Plugin fails to check calls from sandboxed scripts to methods dynamically added to classes at runtime, allowing sandbox bypass and execution outside the sandbox where the prerequisite dynamically added method exists. This aligns directly with Script Security control failure and controller execution.

·        CVE-2026-92128 — Direct Behavioral Coverage — Script Security Plugin downloads a URL-based classpath JAR twice, approving the first download and loading the second, creating a TOCTOU condition that can allow arbitrary code execution in the Jenkins controller JVM when an already approved JAR is served from an attacker-controlled server. This aligns directly with Script Security classpath trust, Jenkins-originated retrieval, and controller execution.

·        CVE-2026-92127 — Direct Behavioral Coverage — Script Security Plugin classpath approval behavior can allow attacker-defined classpath content to be approved or used through affected configuration paths, producing arbitrary code execution in the Jenkins controller JVM under the advisory prerequisites. This aligns directly with Script Security trust manipulation, privileged Jenkins configuration, and controller execution.

·        CVE-2026-92126 — Direct Behavioral Coverage — Script Security Plugin fails to reject arbitrary @Builder strategy classes, potentially allowing code execution outside the sandbox at compile time where a suitable class is available on the relevant classpath. This aligns directly with Script Security control failure and controller execution.

·        CVE-2026-92125 — Direct Behavioral Coverage — Script Security Plugin fails to reject @GroovyASTTransformationClass, allowing a sandboxed script to cause an arbitrary AST transformation to execute during compilation before the sandbox is applied. This aligns directly with Script Security bypass and controller execution.

·        CVE-2026-92124 — Direct Behavioral Coverage — Script Security Plugin validates one set of collection elements but performs a Groovy cast against potentially different attacker-controlled elements, enabling sandbox bypass and arbitrary code execution in the Jenkins controller JVM. This aligns directly with Script Security bypass and controller execution.

·        CVE-2026-92123 — Direct Behavioral Coverage — Script Security Plugin fails to intercept operations performed on a null receiver, enabling sandboxed scripts to bypass sandbox protection and execute arbitrary code in the Jenkins controller JVM. This aligns directly with Script Security bypass and controller execution.

·        CVE-2026-92122 — Direct Behavioral Coverage — Script Security Plugin fails to check the method invoked through affected Groovy proxy dispatch, enabling sandboxed scripts to bypass sandbox protection and execute arbitrary code in the Jenkins controller JVM. This aligns directly with Script Security bypass and controller execution.

The September 2 Jenkins advisory adds 22 vulnerabilities assessed as Direct Behavioral Coverage because the material behavior or resulting Jenkins activity aligns directly with the existing Jenkins-specific detection model.

·        CVE-2026-84676 — Direct Behavioral Coverage — Parameterized Remote Trigger Plugin stores tokens unencrypted in job config.xml, allowing users with Item/Extended Read permission or controller-filesystem access to view them. This aligns directly with sensitive Jenkins file access and credential or token exposure represented by the current model. No fix was available at advisory publication.

·        CVE-2026-84674 — Direct Behavioral Coverage — XebiaLabs XL Deploy Plugin fails to perform permission checks on affected endpoints, allowing users with Overall/Read permission to enumerate Jenkins credential IDs. This aligns directly with Jenkins credential activity and privileged request behavior.

·        CVE-2026-84671 — Direct Behavioral Coverage — File Parameter Plugin path traversal permits arbitrary controller-file writes and can lead to remote code execution, aligning directly with sensitive filesystem activity and controller execution.

·        CVE-2026-84670 — Direct Behavioral Coverage — Performance Plugin deserializes attacker-controlled cached performance data in a manner that permits attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller, aligning directly with controller execution.

·        CVE-2026-84669 — Direct Behavioral Coverage — Allure Plugin path traversal allows applicable users to read arbitrary Jenkins-controller files, aligning directly with sensitive controller-file access.

·        CVE-2026-84668 — Direct Behavioral Coverage — SAML Plugin access-control failure permits attacker-controlled identity-provider metadata and can allow authentication as arbitrary Jenkins users, aligning directly with user impersonation and subsequent privileged Jenkins activity.

·        CVE-2026-84667 — Direct Behavioral Coverage — ThinBackup Plugin access-control failure permits attacker-controlled backup locations and inclusion of arbitrary Jenkins-controller files in backups, aligning directly with plugin manipulation and sensitive-file activity.

·        CVE-2026-84666 — Direct Behavioral Coverage — Job Configuration History Plugin access-control failure permits changes to history storage and recording behavior, aligning directly with plugin configuration manipulation and Jenkins control-plane state changes.

·        CVE-2026-84663 — Direct Behavioral Coverage — Pipeline: Groovy Libraries Plugin CSRF permits deletion of shared-library caches, aligning directly with Jenkins pipeline and shared-library manipulation.

·        CVE-2026-84661 — Direct Behavioral Coverage — Pipeline: Build Step Plugin fails to enforce Item/Cancel permission when waitForBuild abort propagation cancels downstream builds, aligning directly with unauthorized job-control activity.

·        CVE-2026-84660 — Direct Behavioral Coverage — Pipeline: Build Step Plugin fails to enforce Item/Cancel permission when canceling downstream builds through the build step, aligning directly with unauthorized job-control activity.

·        CVE-2026-84659 — Direct Behavioral Coverage — Script Security Plugin access-control weakness permits disabling forced global Groovy sandbox use, aligning directly with Jenkins security-control and plugin-configuration manipulation.

·        CVE-2026-84658 — Direct Behavioral Coverage — Script Security Plugin 1412.v7737b_3405f86 and earlier uses a data-bound constructor that loads script-approval configuration, allowing attackers able to submit certain forms to read that configuration. This aligns directly with unauthorized access to security-control configuration and privileged Jenkins configuration activity.

·        CVE-2026-84657 — Direct Behavioral Coverage — Jenkins CLI fails to enforce Item/Cancel permission under the documented merged-build condition, allowing unauthorized cancellation of another user's build and aligning directly with job-control activity.

·        CVE-2026-84656 — Direct Behavioral Coverage — Jenkins fails to enforce Item/Read permission on an affected endpoint, allowing unauthorized access to build parameter names and values and aligning directly with sensitive Jenkins data access.

·        CVE-2026-84654 — Direct Behavioral Coverage — Jenkins and Stapler form binding can modify public static configuration fields, creating Jenkins-wide configuration effects aligned directly with suspicious configuration submission and privileged control-plane changes.

·        CVE-2026-84652 — Direct Behavioral Coverage — Jenkins remember-me authentication can preserve a session fixed by a same-site attacker, allowing subsequent access as the victim. The resulting anomalous authenticated-user context and privileged Jenkins activity align directly with the existing model.

·        CVE-2026-84651 — Direct Behavioral Coverage — Jenkins REST API or CLI agent configuration updates can overwrite a different agent, allowing takeover of that agent and access to its inbound-agent secret and environment variables. This aligns directly with privileged Jenkins requests, credential access, and subsequent CI/CD execution activity.

·        CVE-2026-84650 — Direct Behavioral Coverage — Jenkins unsafe deserialization permits attacker-controlled transient configuration-field values, aligning directly with suspicious configuration submission and Jenkins control-plane manipulation.

·        CVE-2026-84649 — Direct Behavioral Coverage — Jenkins weekly 2.447 through 2.579 and LTS 2.452.1 through 2.568.2 include Stapler behavior that exposes a user's CSRF crumb through dynamically generated JavaScript resources to an attacker able to serve content on the same site as Jenkins. The attacker can use the obtained crumb to perform Jenkins actions on behalf of the targeted user. The existing model explicitly includes crumb anomalies, unusual authenticated-user context, and consequential privileged Jenkins activity.

·        CVE-2026-84647 — Direct Behavioral Coverage — Jenkins and Stapler form binding permits attackers with Overall/Read permission to instantiate configuration-related object types not intended for the target field, aligning directly with suspicious Jenkins configuration submission and privileged control-plane behavior.

·        CVE-2026-84645 — Direct Behavioral Coverage — Jenkins deserialization of crafted nested configuration objects can expose an improperly protected Script Console and result in remote code execution, aligning directly with suspicious configuration submission, Script Console access, controller execution, credential activity, sensitive-file activity, and downstream CI/CD behavior.

The September 16 Jenkins advisory adds nine vulnerabilities assessed as Coverage With Adaptation because the current behavioral model remains relevant, but plugin-, browser-, credential-, OAuth-, webhook-, destination-, or identity-specific localization is required to identify the initiating behavior reliably.

·        CVE-2026-92141 — Coverage With Adaptation — Keycloak Authentication Plugin does not restrict the redirect URL after login, allowing attacker-controlled Jenkins links to redirect users to another site after successful authentication. Adaptation is required for affected plugin state, authentication flow, redirect target, browser activity, and downstream phishing or credential-use context.

·        CVE-2026-92140 — Coverage With Adaptation — Gitee Plugin fails to escape sender names supplied through push-webhook payloads when rendering build causes, producing stored XSS. Adaptation is required for plugin state, webhook provenance, sender content, build-cause rendering, browser activity, and Content Security Policy state.

·        CVE-2026-92139 — Coverage With Adaptation — Bitbucket Push and Pull Request Plugin trusts URL values supplied through webhook payloads and uses configured Bitbucket credentials when connecting to those destinations, allowing credential capture. Adaptation is required for plugin state, webhook provenance, payload URL, configured Bitbucket endpoint, credential use, Jenkins-originated network activity, and downstream Bitbucket context.

·        CVE-2026-92138 — Coverage With Adaptation — Bitbucket Server Integration Plugin reads the OAuth callback URL from submitted form data instead of the server-side stored request token, allowing manipulated submissions to redirect OAuth token and verifier material to an attacker-selected destination under the documented prerequisites. Adaptation is required for plugin state, OAuth consumer state, stored request token, submitted callback, browser redirect, token or verifier use, and resulting Bitbucket access.

·        CVE-2026-92136 — Coverage With Adaptation — OWASP Dependency-Check Plugin fails to escape CWE values from Dependency-Check reports rendered in Jenkins, producing stored XSS. Adaptation is required for plugin state, report provenance, CWE content, rendered-page context, browser activity, and Content Security Policy state.

·        CVE-2026-92135 — Coverage With Adaptation — Coverage Plugin allows an attacker with Item/Configure permission to submit a javascript: scheme coverage result identifier through the REST API, producing stored XSS. Adaptation is required for plugin state, REST configuration provenance, result identifier, rendered-page context, browser activity, and Content Security Policy state.

·        CVE-2026-92134 — Coverage With Adaptation — Warnings Plugin allows an attacker with Item/Configure permission to submit a javascript: scheme analysis result identifier through the REST API, producing stored XSS. Adaptation is required for plugin state, REST configuration provenance, result identifier, rendered-page context, browser activity, and Content Security Policy state.

·        CVE-2026-92133 — Coverage With Adaptation — GitLab Plugin caches API clients in a manner that can confuse credentials with the same identifier resolved from different folder contexts, potentially exposing GitLab API token credentials from another folder. Adaptation is required for plugin state, Jenkins folder hierarchy, credential identifier and scope, API-client cache state, job context, and resulting GitLab activity.

·        CVE-2026-92132 — Coverage With Adaptation — Gradle Plugin can request build-scan data from an attacker-controlled URL while supplying the globally configured Develocity access key, allowing credential capture. Adaptation is required for plugin state, build-log-controlled scan URL, configured Develocity server, outbound destination, and access-key use.

The September 2 Jenkins advisory adds 11 vulnerabilities assessed as Coverage With Adaptation because the current behavioral model remains relevant, but product-, plugin-, browser-, identity-, API-, destination-, or execution-specific localization is required to identify the initiating behavior reliably.

·        CVE-2026-84677 — Coverage With Adaptation — update-center2 3.18.3 and earlier fails to escape plugin-provided names, descriptions, and version metadata when rendering plugin download-index pages, creating stored XSS in affected self-hosted update sites. Adaptation is required for self-hosted update-site inventory, affected update-center2 version, plugin metadata, rendered-page context, and browser activity. Jenkins stated that it was not aware of a plugin released with malicious content exploiting this vulnerability at advisory publication. update-center2 3.18.4 contains the fix.

·        CVE-2026-84675 — Coverage With Adaptation — TICS Plugin fails to escape attacker-controlled build environment-variable values when constructing an operating-system command, permitting arbitrary command execution on the build agent. Adaptation is required for plugin inventory, environment-variable provenance, build and agent identity, constructed command line, and agent process lineage.

·        CVE-2026-84673 — Coverage With Adaptation — Customizable Header Plugin permits attacker-controlled configuration of an SVG icon containing inline JavaScript, producing stored XSS. Adaptation is required for plugin state, configuration provenance, SVG or JavaScript content, rendered-page context, and affected browser session.

·        CVE-2026-84672 — Coverage With Adaptation — Microsoft Entra ID Plugin can authorize users through non-unique Entra group display names, allowing a group created with a privileged display name to inherit Jenkins permissions. Adaptation is required for Entra group object IDs and display names, group-creation activity, Jenkins authorization grants, authentication, and resulting privileged Jenkins actions.

·        CVE-2026-84665 — Coverage With Adaptation — SonarQube Scanner Plugin 2.18.3 and earlier permits persisted dashboard URLs using the javascript: scheme, creating stored XSS for attackers with Item/Configure permission. Adaptation is required for affected plugin version, persisted dashboard URL, rendered-page context, browser activity, and Content Security Policy state. On Jenkins 2.539 and newer and LTS 2.541.1 and newer, enforcing Content Security Policy protection mitigates the vulnerability. SonarQube Scanner Plugin 2.19.0 restricts dashboard URLs to HTTP and HTTPS and no longer renders previously persisted dashboard URLs using disallowed schemes.

·        CVE-2026-84664 — Coverage With Adaptation — GitLab Plugin allows certain form submissions to overwrite global GitLab connection configuration and connect to an attacker-specified URL using configured GitLab API tokens. Adaptation is required for affected plugin state, configured token context, submitted destination, Jenkins-originated network activity, and downstream GitLab activity.

·        CVE-2026-84662 — Coverage With Adaptation — LDAP Plugin allows affected form submissions to cause Jenkins to connect to attacker-specified URLs without the required permission. Adaptation is required for plugin state, form-submission provenance, destination, Jenkins-originated network activity, and identity context.

·        CVE-2026-84655 — Coverage With Adaptation — Jenkins REST API serialization does not correctly escape attacker-controlled map keys, allowing injection of arbitrary fields into JSON or Python API responses. Adaptation is required for API endpoint, controlled property-name, serialized-response, consuming application, and downstream-effect context.

·        CVE-2026-84653 — Coverage With Adaptation — Jenkins weekly 2.421 through 2.579 and LTS 2.426.1 through 2.568.2 perform insufficient permission checks in the Appearance configuration page, allowing users with Overall/Manage permission to modify options they should not control. Impact depends on installed plugins and configuration. Adaptation is required for affected version, installed plugin state, exact configuration change, rendered content, and downstream effect.

·        CVE-2026-84648 — Coverage With Adaptation — Jenkins 2.579 and earlier and LTS 2.568.2 and earlier fail to escape source, level, and timestamp metadata in the system-log viewer, creating stored XSS exploitable by attackers controlling agent processes. Adaptation is required for agent-process control, malicious log metadata, system-log rendering, browser-session context, and Content Security Policy state. On Jenkins 2.539 and newer and LTS 2.541.1 and newer, enforcing Content Security Policy protection mitigates the vulnerability. Jenkins 2.580 and LTS 2.568.3 escape the affected metadata before rendering it.

·        CVE-2026-84646 — Coverage With Adaptation — Jenkins nested XML deserialization permits attackers with Overall/Read permission to create Jenkins user objects. Jenkins states that these are not login-capable Jenkins accounts. Adaptation is required to distinguish the created objects from normal SCM-associated user objects and from actual authentication or identity compromise.

The model provides Coverage With Adaptation for CVE-2026-63077 because the vulnerability affects TeamCity On-Premises and permits an unauthenticated remote attacker with HTTP or HTTPS access to abuse the agent-polling protocol, bypass authentication checks, and execute arbitrary operating-system commands with the privileges of the TeamCity server process. JetBrains fixed the vulnerability in TeamCity 2025.11.7 and 2026.1.3 and provides a security patch plugin for supported older releases where immediate upgrade is not possible.

Adaptation is required for TeamCity asset and version inventory, application and reverse-proxy logs, agent-polling protocol activity where available, server-process lineage, TeamCity-specific filesystem and credential locations, administrative objects, and connected repository, artifact, cloud, Kubernetes, and deployment integrations.

CISA's August 5, 2026 KEV addition confirms exploitation of CVE-2026-63077 in the wild. JetBrains' subsequent exploitation guidance independently confirms active and attempted exploitation against unpatched TeamCity servers.

The JetBrains Cadence incident provides additional authoritative evidence that this exact vulnerability was successfully exploited against a TeamCity-dependent production environment and produced confirmed downstream personal-data, backup, AWS IAM credential, and S3 exposure, with potential synchronized-source-code exposure. JetBrains' September 3 final investigation update additionally establishes potential exposure of current Cadence storage containing current-user email addresses, project source code, and credentials. This consequence update does not create a separate first-class detection object, change CVE-2026-63077's Coverage With Adaptation classification, or require an S21-S25 rewrite.

The model provides Coverage With Adaptation for CVE-2026-73266 because the vulnerability converts lower-trust tenant-controlled ClusterClaim input into privileged controller-mediated changes affecting ManagedCluster metadata, ManagedClusterSet association, and potentially downstream policy or workload distribution. Adaptation is required for Red Hat Multicluster Engine asset and version context, Kubernetes or OpenShift audit logs, ClusterClaim resource and label changes, originating tenant and service-account identity, clusterclaims-controller reconciliation activity, ManagedCluster metadata, ManagedClusterSet membership, admission decisions, and resulting policy or workload activity. The current S25 content does not directly detect the CVE-2026-73266 ClusterClaim label-propagation primitive without that product-specific localization.

The model provides Coverage With Adaptation for the September 23, 2026 Red Hat Ansible Automation Platform automation-controller cohort because the vulnerabilities convert weaknesses in controller authorization, workflow and job handling, credential and secret boundaries, project synchronization, external requests, session and browser handling, audit provenance, controller execution, and cluster-backed automation into consequences already represented by the TTD. Adaptation is required for Ansible Automation Platform asset and version context, automation-controller identity and authorization state, project and inventory ownership, job-template and workflow permissions, credential scope, instance-group and execution-environment state, container-group pod specifications, controller process lineage, receptor identity, external-integration activity, and Kubernetes or OpenShift audit context.

The TTD is not limited to one CVE, exploit string, request path, user agent, proof-of-concept implementation, actor name, advisory, KEV listing, scanner result, WAF signature, endpoint event, plugin, or victim incident.

Detection Engineering Coverage Interpretation

The S25 detection content provides direct behavioral coverage where observable activity falls inside the TTD's detection model: suspicious Jenkins configuration submission, privileged Jenkins path access, unusual authenticated-user context, crumb anomalies where visible, Script Console activity, credential activity, job activity, plugin activity, controller-side execution, sensitive file access, rare egress, artifact publication, cloud deployment activity, Kubernetes deployment activity, and production release activity.

The September 16 Direct Behavioral Coverage classifications do not require exact exploit-string or vulnerability-specific detections. They apply where the vulnerability's durable observable behavior is already represented by existing Jenkins-specific Script Security, credential, controller-filesystem, Pipeline, privileged-request, and controller-execution signals.

Product-specific qualification for the September 16 Direct Behavioral Coverage set should preserve Jenkins plugin and version context, relevant user or permission state, Script Security sandbox or classpath state where applicable, Pipeline configuration, credential-resolution context, controller filesystem activity, and controller execution evidence. These qualifiers localize the vulnerability-specific path without replacing or expanding the generic S25 rule families.

The September 2 Direct Behavioral Coverage classifications do not require exact exploit-string or vulnerability-specific detection. They apply where the vulnerability's durable observable behavior is already represented by those existing Jenkins-specific signals.

The S25 detection content provides Coverage With Adaptation for related Jenkins, CI/CD, build-system, deployment-system, artifact-publishing, cloud-automation, Kubernetes-deployment, or software-delivery compromise activity where observable behavior aligns to privileged CI/CD abuse, controller execution, credential exposure, job manipulation, plugin persistence, artifact manipulation, source-code abuse, downstream deployment activity, or release-integrity impact but reliable attribution requires additional product-specific telemetry or localization.

For the nine adapted September 16 Jenkins vulnerabilities, required localization may include Gradle and Develocity configuration, GitLab credential scope and cache state, Warnings or Coverage result identifiers, OWASP Dependency-Check report content, browser rendering and Content Security Policy state, Bitbucket OAuth callback state, Bitbucket webhook destination and credential context, Gitee webhook sender content, Keycloak post-login redirect context, or other vulnerability-specific evidence not directly encoded by the current S25 detections.

For the 11 adapted September 2 Jenkins vulnerabilities, required localization may include plugin inventory and version, browser rendering, Content Security Policy state, Entra object IDs and group names, Jenkins-originated destination context, REST API response content, self-hosted update-site metadata, build environment variables, agent process lineage, or other vulnerability-specific context not directly encoded by the current S25 detections.

For CVE-2026-92134, CVE-2026-92135, and CVE-2026-92136, Content Security Policy enforcement state is a material exposure and detection-context qualifier where applicable. CSP mitigation can reduce effective browser-side exploitability but does not replace vulnerable-plugin remediation.

For CVE-2026-84648 and CVE-2026-84665 specifically, Content Security Policy enforcement state is a material exposure and detection-context qualifier. On Jenkins 2.539 and newer and LTS 2.541.1 and newer, enforcing Content Security Policy protection mitigates the respective stored-XSS conditions. CSP mitigation should reduce effective exploitability assessment where enforcement can be proven but should not replace vulnerable-version remediation.

For CVE-2026-63077, the existing controller-execution and downstream CI/CD behaviors remain applicable after TeamCity-specific localization. The current S25 content does not directly detect the TeamCity agent-polling protocol authentication bypass or provide complete TeamCity product telemetry, so the vulnerability remains Coverage With Adaptation.

CISA KEV confirmation, JetBrains' general active-exploitation guidance, the confirmed Cadence incident, and the September 3 final Cadence investigation update increase exploitation certainty, remediation urgency, consequence evidence, and compromise-assessment requirements. They do not create a new first-class detection object or require an S21-S25 rewrite.

For CVE-2026-73266, the existing trusted-controller and downstream Kubernetes control-plane behaviors remain applicable after Red Hat Multicluster Engine-specific localization. The current S25 content does not directly detect unauthorized ClusterClaim label manipulation, clusterclaims-controller-mediated label propagation, or resulting cross-tenant ManagedClusterSet association without MCE and Kubernetes audit-field localization, so the vulnerability remains Coverage With Adaptation. The additional telemetry requirement does not create a new first-class detection object or require an S21-S25 rewrite.

For the 30 adapted Ansible Automation Platform vulnerabilities, existing controller-execution, credential, workflow, repository, cloud, Kubernetes, OpenShift, and downstream infrastructure behaviors remain applicable after automation-controller-specific localization. The current S25 content does not directly identify each Ansible Automation Platform initiating mechanism without product-specific identity, authorization, project, workflow, credential, process, receptor, and cluster context, so all 30 remain Coverage With Adaptation. The additional localization requirement does not create a new first-class detection object or require an S21-S25 rewrite.

Current Coverage Count

Direct Behavioral Coverage

·        CVE-2026-92137 — Robot Framework Plugin path traversal enabling arbitrary Jenkins-controller file creation or replacement and potential remote code execution.

·        CVE-2026-92131 — Pipeline: Groovy Libraries Plugin path traversal and symbolic-link traversal enabling access to files outside the intended SCM checkout on the Jenkins controller.

·        CVE-2026-92130 — Pipeline: Multibranch Plugin improper credential lookup context allowing access to System-scoped Jenkins credentials through resolveScm.

·        CVE-2026-92129 — Script Security Plugin sandbox bypass through dynamically added runtime methods.

·        CVE-2026-92128 — Script Security Plugin classpath TOCTOU condition allowing approved URL-based JAR content to be replaced between approval and execution.

·        CVE-2026-92127 — Script Security Plugin classpath approval bypass enabling attacker-controlled classpath execution under affected configuration paths.

·        CVE-2026-92126 — Script Security Plugin sandbox bypass through unrestricted custom @Builder strategy classes under the required classpath condition.

·        CVE-2026-92125 — Script Security Plugin sandbox bypass through @GroovyASTTransformationClass and pre-sandbox AST transformation execution.

·        CVE-2026-92124 — Script Security Plugin sandbox bypass through inconsistent collection-element validation during Groovy casting.

·        CVE-2026-92123 — Script Security Plugin sandbox bypass through unchecked operations on a null receiver.

·        CVE-2026-92122 — Script Security Plugin sandbox bypass through unchecked Groovy proxy method dispatch.

·        CVE-2026-84676 — Parameterized Remote Trigger Plugin plaintext-token exposure through job config.xml. No fix was available at advisory publication.

·        CVE-2026-84674 — XebiaLabs XL Deploy Plugin missing permission checks enabling Jenkins credential-ID enumeration.

·        CVE-2026-84671 — File Parameter Plugin path traversal enabling arbitrary controller-file write and potential remote code execution.

·        CVE-2026-84670 — Performance Plugin unsafe deserialization enabling arbitrary controller-side code execution.

·        CVE-2026-84669 — Allure Plugin path traversal enabling arbitrary Jenkins-controller file read.

·        CVE-2026-84668 — SAML Plugin access-control failure enabling attacker-controlled identity-provider metadata and authentication as arbitrary users.

·        CVE-2026-84667 — ThinBackup Plugin access-control failure enabling attacker-selected backup destinations and inclusion of arbitrary controller files.

·        CVE-2026-84666 — Job Configuration History Plugin access-control failure enabling unauthorized history-storage and recording-setting changes.

·        CVE-2026-84663 — Pipeline: Groovy Libraries Plugin CSRF enabling deletion of shared-library caches.

·        CVE-2026-84661 — Pipeline: Build Step Plugin missing Item/Cancel permission enforcement affecting downstream-build cancellation through waitForBuild.

·        CVE-2026-84660 — Pipeline: Build Step Plugin missing Item/Cancel permission enforcement affecting downstream-build cancellation through the build step.

·        CVE-2026-84659 — Script Security Plugin access-control failure enabling forced global Groovy sandbox enforcement to be disabled.

·        CVE-2026-84658 — Script Security Plugin improper access control allowing attackers able to submit certain forms to read script-approval configuration.

·        CVE-2026-84657 — Jenkins CLI missing Item/Cancel permission enforcement enabling cancellation of another user's build under the documented merged-build condition.

·        CVE-2026-84656 — Jenkins missing Item/Read permission enforcement enabling unauthorized access to build parameter names and values.

·        CVE-2026-84654 — Jenkins and Stapler form-binding behavior enabling modification of public static configuration fields with Jenkins-wide effects.

·        CVE-2026-84652 — Jenkins remember-me session fixation allowing a same-site attacker to reuse a victim's authenticated Jenkins session.

·        CVE-2026-84651 — Jenkins agent-configuration overwrite enabling takeover of another agent and access to its inbound-agent secret and environment variables.

·        CVE-2026-84650 — Jenkins unsafe deserialization allowing attacker-controlled transient configuration-field values.

·        CVE-2026-84649 — Jenkins cross-origin CSRF-token exposure affecting weekly 2.447 through 2.579 and LTS 2.452.1 through 2.568.2, allowing a same-site attacker to obtain a victim's crumb and perform Jenkins actions in that user's session.

·        CVE-2026-84647 — Jenkins and Stapler form-binding weakness permitting unintended configuration-related object instantiation.

·        CVE-2026-84645 — Jenkins nested-object deserialization leading to improperly protected Script Console access and remote code execution.

·        CVE-2026-53435 — Jenkins controller deserialization vulnerability enabling controller-side exploitation behavior aligned directly with the TTD's Jenkins-specific S21 through S25 detection strategy, including privileged request activity, controller execution, credential access, job or plugin manipulation, sensitive file access, artifact activity, and downstream CI/CD control-plane abuse where observable.

Coverage With Adaptation

·        CVE-2026-94416 — Red Hat Ansible Automation Platform — Coverage With Adaptation. Reliable attribution requires product/version, administrator identity, service-identity, workload-identity, downstream relying-service, and resulting security-impact context while preserving Red Hat's documented authentication, identity, and trust prerequisites. Current authoritative evidence reviewed for this amendment does not establish CISA KEV status or confirmed in-the-wild exploitation.

·        CVE-2026-75884 — Ansible Automation Platform container-group pod_spec_override injection permits privilege escalation into the OpenShift namespace. Adaptation requires automation-controller container-group configuration, submitted pod specifications, originating identity and permissions, service-account context, namespace activity, pod creation, and resulting OpenShift control-plane or secret access.

·        CVE-2026-84474 — Automation-controller provisioning callbacks can expose host_config_key material and trust spoofable X-Forwarded-For host matching, allowing a user with job-template visibility to escalate into execution under the documented conditions. Adaptation requires job-template visibility, provisioning-callback activity, host_config_key exposure, forwarded-address provenance, callback host matching, launch activity, and resulting execution context.

·        CVE-2026-84486 — Unauthenticated debug scheduler-trigger endpoints remain reachable without the required debug guard and can starve the scheduler advisory lock, disrupting job dispatch. Adaptation requires automation-controller endpoint access, repeated scheduler-trigger activity, advisory-lock state, scheduler health, job-dispatch delays, and source-network context.

·        CVE-2026-84499 — Automation-controller can disclose a write-only survey password in plaintext through Schedule or WorkflowJobTemplateNode survey minimum/maximum validation error messages. Adaptation requires affected survey configuration, schedule or workflow-node modification activity, validation failures, response or application-log content, initiating user context, and subsequent credential-use evidence.

·        CVE-2026-84502 — Ansible Automation Platform Project scm_url handling permits argument injection into git ls-remote --upload-pack, enabling remote code execution in the controller-task control-plane pod. Adaptation requires project SCM configuration, attacker-controlled scm_url values, project validation or synchronization activity, git command lineage, controller-task pod execution, and downstream control-plane effects.

·        CVE-2026-84638 — Instance-group attachment to schedules and workflow job-template nodes checks only read permission, allowing restricted or control-plane instance groups to be used and enabling control-plane code execution under the documented prerequisites. Adaptation requires schedule or workflow-node changes, instance-group identity, read-versus-use authorization state, execution placement, control-plane instance-group use, and resulting process activity.

·        CVE-2026-84643 — Project signature-validation credential assignment lacks the required use-role authorization, allowing a project administrator to bind and use another organization's credential. Adaptation requires project administration activity, signature-validation credential assignment, credential ownership and use-role state, cross-organization context, project synchronization, and resulting credential use.

·        CVE-2026-84644 — The Thycotic Secret Server external-credential plugin test endpoint accepts a caller-controlled server URL, allowing controller-web-process server-side request forgery. Adaptation requires external-credential configuration, test-endpoint activity, submitted server_url values, controller-originated connections, destination classification, requesting identity, and any resulting credential or internal-service access.

·        CVE-2026-84679 — The AWX_TASK_ENV setting permits arbitrary environment variables to reach automation-controller web and task control-plane processes, enabling external-credential TLS interception and code execution through dangerous process-environment settings. Adaptation requires AWX_TASK_ENV changes, administrator identity, injected environment variables, controller web or task process environment, outbound TLS behavior, credential use, and resulting process execution.

·        CVE-2026-84680 — Organization Galaxy credential attachment checks only read permission, allowing an organization administrator with read-only visibility to bind and server-side-use another tenant's Automation Hub API token. Adaptation requires organization configuration changes, Galaxy credential ownership and permissions, token attachment, Automation Hub requests, tenant context, and resulting token use.

·        CVE-2026-84683 — Job stdout HTML rendering permits stored cross-site scripting through ANSI OSC 8 hyperlink sequences using javascript: anchors, creating a session-takeover path. Adaptation requires job-output provenance, OSC 8 hyperlink content, rendered stdout access, browser-session context, affected user identity, and consequential session or privileged action.

·        CVE-2026-84684 — Constructed-inventory input attachment checks only read permission, allowing a read-only user to clone another tenant's hosts and secrets and run ad hoc commands against them. Adaptation requires constructed-inventory configuration, source-inventory ownership and permission state, host and secret propagation, ad hoc command activity, originating identity, and cross-tenant effects.

·        CVE-2026-84686 — Notification-template password fields can be decrypted by replaying encrypted values across subfields, exposing plaintext Slack, PagerDuty, Twilio, AWS SNS, or Grafana credentials. Adaptation requires notification-template administration, encrypted-value reuse across fields, template modification or validation activity, affected credential type, and subsequent external-service access.

·        CVE-2026-84689 — Bulk job launch permits a workflow node's job reference to be set to an arbitrary unified job, allowing a low-privileged user to cancel or read metadata from jobs belonging to other organizations. Adaptation requires bulk-launch requests, workflow-node job references, originating identity and permissions, target unified-job ownership, cancellation or metadata-access activity, and cross-organization context.

·        CVE-2026-84691 — Automation-controller API 4XX error-log configuration is vulnerable to format-string injection that can disclose the Django SECRET_KEY and database credentials to an administrator. Adaptation requires relevant logging configuration, attacker-controlled format content, API error generation, application-log access, administrative identity, exposed secret material, and subsequent credential use.

·        CVE-2026-84692 — Workflow job-template node execution authorization can be bypassed by creating a node with a null unified_job_template and subsequently patching it, allowing a workflow administrator to execute another tenant's job template with the victim's credentials. Adaptation requires workflow-node creation and patch sequencing, null-to-populated template transitions, user authorization, target-template ownership, credential context, and resulting job execution.

·        CVE-2026-84703 — Execution-environment credential assignment lacks the required use-permission check, allowing an organization execution-environment administrator to bind and disclose another organization's container-registry credential. Adaptation requires execution-environment administration, credential foreign-key changes, credential ownership and use permissions, image-registry activity, cross-organization context, and subsequent registry access.

·        CVE-2026-84706 — Credential Type environment injectors fail to block process-hijacking variables such as BASH_ENV and LD_PRELOAD, allowing code execution inside the execution environment. Adaptation requires credential-type creation or modification, injected environment-variable content, job-template credential use, execution-environment process lineage, originating identity, and resulting code execution.

·        CVE-2026-84707 — Smart Inventory host_filter ORM traversal can expose JobEvent or AdHocCommandEvent event_data and stdout to users without permission on the underlying job, enabling blind cross-tenant extraction of job output. Adaptation requires Smart Inventory filter activity, ORM traversal patterns, target event or job ownership, repeated count-oracle behavior, requesting identity, and reconstructed output.

·        CVE-2026-84708 — Container-group pod_spec_override behavior can mint the automation-controller ServiceAccount token and mount control-plane namespace secrets into job pods despite automountServiceAccountToken:false, enabling control-plane secret and identity compromise. Adaptation requires container-group pod specifications, service-account token projection, secret mounts, created job pods, namespace access, and resulting token or secret use.

·        CVE-2026-84709 — CredentialType injector validation renders attacker-supplied Jinja2 templates synchronously in the web worker, allowing uncontrolled resource consumption and denial of service. Adaptation requires credential-type API activity, injected Jinja2 content, web-worker CPU or memory behavior, HTTP 500 responses, requesting identity, and controller-service degradation.

·        CVE-2026-84711 — Project scm_branch or scm_refspec argument injection into git during project synchronization permits arbitrary file reads on the synchronization host, potentially exposing the control-plane ServiceAccount token, SECRET_KEY, and database credentials and enabling broader Ansible Automation Platform or Kubernetes namespace compromise. Adaptation requires project SCM field changes, project-sync execution, git command arguments, synchronization-host file access, secret exposure, and downstream control-plane activity.

·        CVE-2026-84712 — The unauthenticated /api/v2/ping/ endpoint discloses automation-mesh instance topology and instance-group membership. Adaptation requires unauthenticated ping requests, exposed topology or group information, source-network context, follow-on targeting activity, and correlation with receptor or instance-group infrastructure.

·        CVE-2026-84714 — Incomplete sanitize_jinja() filtering permits Jinja template injection through ad hoc module_args, Machine credential fields, and Host names that later reach ansible-core templating in the execution environment. Adaptation requires affected object changes, attacker-controlled Jinja syntax, ad hoc or job execution, credential or host provenance, execution-environment rendering, and resulting command or data-access behavior.

·        CVE-2026-84716 — The automation-controller instance install_bundle path issues long-lived, non-revocable receptor mesh-CA certificates for caller-chosen hostnames, including case-variant names capable of impersonating existing identities. Adaptation requires install_bundle requests, requesting identity, chosen hostname, certificate issuance, receptor mesh identity, certificate lifetime, and subsequent mesh connections.

·        CVE-2026-84717 — The Bitbucket Data Center webhook receiver exposes an unauthenticated HTTP response oracle that distinguishes webhook-enabled job templates through 200-versus-403 responses. Adaptation requires unauthenticated webhook probing, response-code patterns, targeted template identifiers, source-network context, and follow-on job-template targeting.

·        CVE-2026-84718 — Unrestricted trust in X-Forwarded-For permits client-IP spoofing in automation-controller audit and access logs. Adaptation requires forwarded-header values, reverse-proxy configuration, socket-source address, audit and access-log comparison, requesting identity where available, and downstream attribution impact.

·        CVE-2026-84719 — WorkflowJobTemplate copy processing fails to sanitize instance-group authorization during deep copy, allowing an InstanceGroup use-role bypass and potential execution on control-plane instance groups. Adaptation requires workflow-template copy activity, copied instance-group references, source and destination authorization, execution placement, control-plane group use, and resulting controller-side execution.

·        CVE-2026-84720 — WorkflowJobNode.ancestor_artifacts is searchable when it should not be, enabling ORM-traversal count-oracle disclosure of no_log set_stats artifacts. Adaptation requires API filtering activity, ancestor_artifacts traversal patterns, target workflow or job ownership, repeated count-oracle requests, requesting identity, and reconstruction of protected artifact data.

·        CVE-2026-84724 — SystemJob extra_vars.days permits argument injection into the uncontainerized control-plane awx-manage process. Adaptation requires System Job creation or launch, extra_vars.days values, initiating identity and permissions, awx-manage command arguments, control-plane process lineage, and resulting command behavior.

·        CVE-2026-92141 — Keycloak Authentication Plugin open redirect after successful Jenkins authentication. Plugin, login-flow, redirect-target, browser, and downstream phishing context are required.

·        CVE-2026-92140 — Gitee Plugin stored XSS through unescaped sender names from push-webhook payloads displayed in build causes. Webhook, rendering, browser, and CSP context are required.

·        CVE-2026-92139 — Bitbucket Push and Pull Request Plugin SSRF allowing attacker-controlled webhook destinations to receive configured Bitbucket credentials. Webhook, destination, credential, network, and downstream Bitbucket context are required.

·        CVE-2026-92138 — Bitbucket Server Integration Plugin OAuth callback manipulation enabling OAuth token and verifier redirection under the documented prerequisites. OAuth consumer, request-token, callback, browser, and downstream access context are required.

·        CVE-2026-92136 — OWASP Dependency-Check Plugin stored XSS through unescaped CWE values in rendered reports. Plugin, report, browser, and CSP context are required.

·        CVE-2026-92135 — Coverage Plugin stored XSS through javascript: coverage-result identifiers submitted through the REST API. Plugin, REST configuration, rendering, browser, and CSP context are required.

·        CVE-2026-92134 — Warnings Plugin stored XSS through javascript: analysis-result identifiers submitted through the REST API. Plugin, REST configuration, rendering, browser, and CSP context are required.

·        CVE-2026-92133 — GitLab Plugin API-client cache confusion allowing credential-scope crossover where the same credential ID resolves from different folder contexts. Folder, credential, cache, job, and downstream GitLab context are required.

·        CVE-2026-92132 — Gradle Plugin SSRF allowing an attacker-controlled build-scan URL to receive the configured Develocity access key. Plugin, build-log, destination, Develocity, and credential context are required.

·        CVE-2026-84677 — update-center2 stored XSS affecting self-hosted Jenkins update sites through unescaped plugin-provided metadata. Self-hosted update-site, metadata, rendering, and browser context are required.

·        CVE-2026-84675 — TICS Plugin command injection through attacker-controlled build environment-variable values. Plugin, build, agent, command-line, and execution-lineage localization are required.

·        CVE-2026-84673 — Customizable Header Plugin stored XSS through attacker-controlled SVG or JavaScript configuration. Plugin, configuration, rendering, and browser-session context are required.

·        CVE-2026-84672 — Microsoft Entra ID Plugin privilege escalation through non-unique Entra group display-name matching. Entra identity, group object-ID, Jenkins authorization, and privileged-use correlation are required.

·        CVE-2026-84665 — SonarQube Scanner Plugin stored XSS through persisted javascript: dashboard URLs. Plugin, item-configuration, persisted URL, browser, and CSP context are required. On Jenkins 2.539 and newer and LTS 2.541.1 and newer, enforcing Content Security Policy protection mitigates the vulnerability.

·        CVE-2026-84664 — GitLab Plugin SSRF using administrator-configured GitLab API tokens. Plugin, token, destination, Jenkins-originated network, and downstream GitLab context are required.

·        CVE-2026-84662 — LDAP Plugin SSRF to attacker-specified destinations. Plugin, form-submission, destination, network, and identity context are required.

·        CVE-2026-84655 — Jenkins REST API map-key injection into JSON or Python responses. API endpoint, attacker-controlled property, serialized-response, and consuming-system context are required.

·        CVE-2026-84653 — Jenkins Appearance configuration permission failure affecting weekly 2.421 through 2.579 and LTS 2.426.1 through 2.568.2. Installed-plugin, configuration-option, resulting-content, and browser or downstream effect context are required.

·        CVE-2026-84648 — Jenkins system-log viewer stored XSS through unescaped source, level, or timestamp metadata controlled through an agent process. Agent-control, rendered-log, browser, and CSP context are required. On Jenkins 2.539 and newer and LTS 2.541.1 and newer, enforcing Content Security Policy protection mitigates the vulnerability.

·        CVE-2026-84646 — Jenkins nested deserialization allowing creation of non-login user objects. Object-submission and user-object context are required to distinguish the behavior from normal SCM-associated user objects.

·        CVE-2026-73266 — Red Hat Multicluster Engine for Kubernetes clusterclaims-controller confused-deputy behavior allowing an authenticated tenant to manipulate ClusterClaim labels that propagate into ManagedCluster objects, enabling unauthorized cross-tenant ManagedClusterSet association and potential policy or workload injection into victim clusters. Red Hat rates the vulnerability Important with a CVSS v3 base score of 7.1.

·        CVE-2026-63077 — TeamCity On-Premises unauthenticated agent-polling protocol abuse and authentication-check bypass enabling arbitrary operating-system command execution with the privileges of the TeamCity server process, with conditional access to configuration, credentials, projects, builds, agents, plugins, artifacts, repositories, cloud environments, Kubernetes environments, and production-deployment workflows. CISA added the vulnerability to the Known Exploited Vulnerabilities Catalog on August 5, 2026, based on evidence of active exploitation. Current CISA KEV metadata also marks the vulnerability as used in known ransomware campaigns. JetBrains subsequently confirmed active and attempted exploitation against unpatched TeamCity servers and confirmed successful exploitation of CVE-2026-63077 against its Cadence environment during August 8-24, 2026, with confirmed personal-data extraction, compromise of a 2024 server backup, compromise of AWS IAM users and associated credentials or secrets, S3 data access, potential synchronized-source-code exposure, and potential exposure of current Cadence storage containing current-user email addresses, project source code, and credentials.

Current coverage is 34 Direct Behavioral Coverage CVEs and 53 Coverage With Adaptation CVEs, for 87 total CVEs represented by this TTD.

The September 16 Jenkins advisory adds 20 CVEs to the previous register: 11 Direct Behavioral Coverage CVEs and nine Coverage With Adaptation CVEs.

The September 2 Jenkins advisory adds 33 CVEs to the earlier register: 22 Direct Behavioral Coverage CVEs and 11 Coverage With Adaptation CVEs.

The September 23 Red Hat Ansible Automation Platform amendment adds 30 automation-controller CVEs as Coverage With Adaptation. It does not change the 34 Direct Behavioral Coverage CVE count.

The September 24 Red Hat Ansible Automation Platform amendment adds CVE-2026-94416 as Coverage With Adaptation, increasing the adapted count from 52 to 53 and the total represented CVE count from 86 to 87. It does not change the 34 Direct Behavioral Coverage CVE count.

The September 16 Jenkins Coverage With Adaptation entries remain adapted because their durable behavior aligns to the existing Jenkins or CI/CD model, but the initiating mechanism cannot be attributed reliably without additional vulnerability-specific context.

CVE-2026-92132 requires Gradle Plugin, build-scan URL, configured Develocity server, Jenkins-originated destination, and access-key context.

CVE-2026-92133 requires GitLab Plugin folder, credential-ID, credential-resolution, API-client-cache, job, and downstream GitLab context.

CVE-2026-92134 requires Warnings Plugin result-ID, REST configuration, rendered-page, Content Security Policy, and browser context.

CVE-2026-92135 requires Coverage Plugin result-ID, REST configuration, rendered-page, Content Security Policy, and browser context.

CVE-2026-92136 requires OWASP Dependency-Check Plugin report provenance, CWE-value, rendered-page, Content Security Policy, and browser context.

CVE-2026-92138 requires Bitbucket Server Integration OAuth-consumer, stored request-token, submitted callback, browser redirect, token or verifier, and downstream Bitbucket context.

CVE-2026-92139 requires Bitbucket Push and Pull Request webhook, payload URL, configured credential, destination, and Jenkins-originated network context.

CVE-2026-92140 requires Gitee webhook sender, build-cause rendering, Content Security Policy, and browser context.

CVE-2026-92141 requires Keycloak Authentication Plugin login-flow, redirect-target, browser-navigation, and downstream phishing or credential-use context.

The September 2 Jenkins Coverage With Adaptation entries remain adapted because their durable behavior aligns to the existing Jenkins or CI/CD model, but the initiating mechanism cannot be attributed reliably without additional vulnerability-specific context.

CVE-2026-84646 requires nested-deserialization and non-login Jenkins user-object context.

CVE-2026-84648 requires agent-process, system-log metadata, page-rendering, Content Security Policy, and browser context. Where Jenkins 2.539 or newer or LTS 2.541.1 or newer is in use, investigators should establish whether Content Security Policy protection was actually enforced because enforcement mitigates the vulnerability.

CVE-2026-84653 requires Appearance configuration, installed-plugin, permission, and downstream rendering or configuration context and applies only to Jenkins weekly 2.421 through 2.579 and LTS 2.426.1 through 2.568.2.

CVE-2026-84655 requires REST API map-property and serialized-response context.

CVE-2026-84662 requires LDAP Plugin, form-submission, Jenkins-originated destination, and network context.

CVE-2026-84664 requires GitLab Plugin, configured API-token, destination, and Jenkins-originated network context.

CVE-2026-84665 requires SonarQube Scanner Plugin, persisted dashboard URL, Content Security Policy, and browser context. Where Jenkins 2.539 or newer or LTS 2.541.1 or newer is in use, investigators should establish whether Content Security Policy protection was actually enforced because enforcement mitigates the vulnerability.

CVE-2026-84672 requires Microsoft Entra ID group object-ID and display-name correlation with Jenkins authorization and resulting privileged activity.

CVE-2026-84673 requires Customizable Header Plugin configuration and browser-rendering context.

CVE-2026-84675 requires TICS Plugin build-environment, build-agent, command-line, and execution-lineage context.

CVE-2026-84677 requires self-hosted update-center2 deployment, malicious plugin metadata, rendered-page, and browser context.

CVE-2026-84649 remains Direct Behavioral Coverage but applies only to Jenkins weekly 2.447 through 2.579 and LTS 2.452.1 through 2.568.2.

CVE-2026-84658 remains Direct Behavioral Coverage because the material observable condition is unauthorized reading of Script Security script-approval configuration through certain form submissions. The vulnerability does not itself disable the Groovy sandbox; that separate behavior is CVE-2026-84659.

CVE-2026-73266 remains Coverage With Adaptation because the existing trusted-controller and downstream Kubernetes behavior model applies only after Red Hat Multicluster Engine-specific localization. Adaptation is required for MCE inventory, Kubernetes or OpenShift audit records, ClusterClaim create/update/patch activity, metadata and label changes, originating tenant and service-account identity, clusterclaims-controller reconciliation, ManagedCluster metadata, ManagedClusterSet membership, admission decisions, and downstream policy or workload activity. The vulnerability does not require an S21-S25 rewrite because its durable detection value remains the conversion of lower-trust input into privileged controller-mediated control-plane action.

CVE-2026-63077 remains Coverage With Adaptation because the existing controller-execution and downstream CI/CD behavioral model applies only after TeamCity-specific localization. Adaptation is required for TeamCity asset and version inventory, application and reverse-proxy logs, agent-polling protocol activity where available, server-process lineage, TeamCity-specific filesystem and credential locations, administrative objects, and connected repository, artifact, cloud, Kubernetes, and deployment integrations.

CISA KEV confirmation, JetBrains' general active-exploitation reporting, the confirmed Cadence incident, and the September 3 final Cadence investigation update change exploitation certainty, consequence evidence, remediation urgency, and compromise-assessment requirements but do not create a new first-class detection object or require an S21-S25 rewrite.

Active Exploitation and KEV Qualification

As of the current September 24, 2026 review, the Jenkins September 16 advisory establishes the affected plugins, affected and fixed versions, technical behaviors, and remediation state for CVE-2026-92122 through CVE-2026-92141.

The authoritative Jenkins advisory does not establish active malicious exploitation of the 20 September 16 vulnerabilities.

No September 16 Jenkins CVE is represented as CISA KEV-confirmed in this TTD as of the current review.

The absence of confirmed exploitation or KEV status does not eliminate remediation urgency for vulnerabilities capable of Script Security sandbox bypass, arbitrary Jenkins-controller JVM execution, arbitrary controller-file creation or replacement, protected credential exposure, credential-bearing SSRF, OAuth token hijacking, or related control-plane trust failures.

The September 2 Jenkins advisory establishes the affected products, affected and fixed versions, technical behaviors, and remediation state for CVE-2026-84645 through CVE-2026-84677.

The authoritative Jenkins advisory does not establish active malicious exploitation of the 33 September 2 vulnerabilities.

No September 2 Jenkins CVE is represented as CISA KEV-confirmed in this TTD as of the current review.

Jenkins states that, at publication, its security team was not aware of a plugin released with malicious content exploiting CVE-2026-84677.

The absence of confirmed exploitation or KEV status does not eliminate remediation urgency for vulnerabilities capable of Script Console access, controller remote-code execution, arbitrary controller-file writes, arbitrary controller-file reads, agent takeover, authentication as arbitrary users, Jenkins privilege escalation, command execution on build agents, credential-related exposure, or security-control weakening.

CISA added CVE-2026-63077 to the Known Exploited Vulnerabilities Catalog on August 5, 2026, based on evidence of active exploitation. Current CISA KEV metadata also marks the vulnerability as used in known ransomware campaigns. This materially superseded the prior assessment that available reporting did not establish exploitation and that the vulnerability was not KEV-confirmed. Organizations should treat affected or previously affected internet-accessible TeamCity On-Premises servers as requiring urgent remediation and a risk-based review for potential compromise before the applicable fix or security patch plugin was applied.

JetBrains subsequently reported active exploitation and attempted exploitation targeting unpatched TeamCity servers. That reporting establishes a broader exploitation condition independent of the later Cadence victim disclosure.

JetBrains separately confirmed a specific successful exploitation case involving its Cadence service.

·        Affected server: api.cadence.jetbrains.com.

·        Affected period: August 8, 2026 through August 24, 2026.

·        Exploitation path: the Cadence server used TeamCity to orchestrate workloads, remained vulnerable to CVE-2026-63077, and was successfully exploited through that vulnerability.

·        Discovery: JetBrains discovered the exploitation on August 23, 2026.

·        Containment: JetBrains took the affected server offline on August 24, 2026.

·        Confirmed personal-data impact: threat actors accessed and extracted personal data from the affected environment, including usernames, real names, email addresses, last-login timestamps, and last-accessed IP addresses.

·        Confirmed backup impact: threat actors compromised a full backup of the Cadence server dating from 2024.

·        Confirmed credential impact: multiple AWS IAM users and associated credentials or secrets used with Cadence were compromised; those credentials were present in the compromised 2024 backup.

·        Confirmed cloud-storage impact: threat actors accessed files stored in S3 buckets within JetBrains AWS accounts used by Cadence.

·        Potential source-code impact: source code synchronized from PyCharm projects to the affected server may have been accessed.

·        Credential-assurance impact: credentials or secrets stored in Cadence, contained in the compromised backup, or made available to executions on the affected server should be considered compromised and revoked or rotated.

·        Potentially affected credential classes include cloud credentials, source-control credentials and tokens, package-registry credentials, container-registry credentials, Slack tokens, webhooks, API tokens, SSH or deployment keys, service-account credentials, signing keys or certificates, and credentials for other external systems used by Cadence executions.

·        JetBrains invalidated access tokens used by the Cadence plugin in PyCharm to connect to Cadence.

The August 31, 2026 Cadence update initially stated that JetBrains had not identified additional compromised resources or data and that there was no evidence at that time that the threat actor extracted data, including secrets, from the current Cadence environment.

JetBrains' September 3, 2026 final investigation update supersedes that current-state qualifier.

·        JetBrains determined that the threat actor obtained access that could have allowed them to reach storage used by the current Cadence environment.

·        That storage contained data associated with current Cadence users, including email addresses, project source code, and credentials.

·        JetBrains is treating the data stored there as potentially exposed.

·        JetBrains did not identify additional affected users beyond those already contacted.

·        The September 3 finding does not establish confirmed extraction of current project source code, current credentials, or every object in current Cadence storage.

·        JetBrains states that the investigation has concluded.

The Cadence incident provides authoritative environment-specific evidence of successful exploitation and downstream impact. It does not establish that every exposed TeamCity server was successfully exploited or that every exploited TeamCity environment experienced credential, data, repository, artifact, cloud, Kubernetes, or production-deployment compromise.

As of the current review, CVE-2026-73266 is not represented as a CISA KEV item in this TTD, and the current Red Hat vulnerability record does not establish active exploitation. Its inclusion in this coverage register remains based on behavioral alignment, cross-tenant control-plane impact, and detection-adaptation value rather than KEV or confirmed active-exploitation status.

As of this amendment, the 30 September 23 Ansible Automation Platform automation-controller CVEs are not represented as CISA KEV items in this TTD, and the authoritative Red Hat material reviewed for the amendment does not establish confirmed in-the-wild exploitation for the cohort. Their inclusion is based on behavioral alignment and detection-adaptation value rather than KEV or confirmed active-exploitation status.

As of this amendment, CVE-2026-94416 is not represented as a CISA KEV item in this TTD, and current authoritative evidence reviewed for this amendment does not establish confirmed in-the-wild exploitation. Its inclusion is based on behavioral alignment and detection-adaptation value rather than KEV or confirmed active-exploitation status.

Current CISA KEV-confirmed count represented by this TTD is 1.

·        CVE-2026-63077 — CISA KEV-confirmed August 5, 2026 based on evidence of active exploitation; current CISA KEV metadata marks the vulnerability as used in known ransomware campaigns.

The September 16 Jenkins additions, September 2 Jenkins additions, September 23 Ansible Automation Platform additions, September 24 CVE-2026-94416 addition, and September 3 Cadence consequence update do not change the current KEV count.

Non-Coverage Conditions

Non-coverage applies where related activity does not produce observable Jenkins configuration submission, privileged Jenkins request handling, user or session abuse, Script Console access, credential activity, arbitrary controller file read or write, job modification, plugin modification, controller-side or agent-side execution, sensitive file access, rare egress, artifact publication, source-code activity, cloud activity, Kubernetes activity, production deployment activity, or CI/CD trust impact.

Affected Jenkins core or plugin version status, a scanner result, plugin presence, missing patch state, or theoretical exploitability alone should not be represented as successful exploitation.

For the September 16 Jenkins vulnerabilities, affected-plugin status, required attacker permissions, scanner findings, sandboxed-script presence, credential configuration, webhook receipt, OAuth activity, stored report content, or an external redirect alone should not be represented as successful controller execution, credential theft, controller-file compromise, browser-side exploitation, OAuth-token hijacking, downstream source-control compromise, or broader CI/CD compromise without sufficient vulnerability-specific and consequential evidence.

For the September 2 Jenkins vulnerabilities, individual browser events, configuration changes, job activity, agent changes, outbound requests, file accesses, credential-ID enumeration, token exposure conditions, or identity changes should not be represented as successful downstream compromise without sufficient affected-version, source, authorization, sequence, and consequence evidence.

For CVE-2026-84648 and CVE-2026-84665, vulnerable-version status without confirmation of the applicable browser-rendering path and Content Security Policy state should not be represented as successful XSS exploitation. Where CSP protection was enforced on Jenkins 2.539 or newer or LTS 2.541.1 or newer, the vendor identifies that control as mitigating the vulnerability.

Activity limited to unrelated CI/CD systems, unrelated web applications, identity-only anomalies, cloud-only anomalies, network-only anomalies, isolated scanner findings, availability-only Jenkins errors, benign administrative maintenance, or unrelated software flaws should not be represented as covered by this TTD.

For TeamCity, affected-version status, prior external reachability, scanning, KEV status, or an uncorroborated agent-polling request alone should not be represented as successful command execution, credential access, workflow manipulation, artifact compromise, or downstream repository, cloud, Kubernetes, or production compromise.

The JetBrains Cadence incident should not be used to infer equivalent downstream impact for unrelated TeamCity exploitation without environment-specific supporting evidence. Cadence provides a confirmed consequence example, not a universal victim-outcome assumption.

The September 3 potential-current-storage exposure finding should not be represented as confirmed extraction of current project source code, current credentials, or all data stored in the current Cadence environment unless additional evidence establishes those outcomes.

For CVE-2026-73266, affected-product status, tenant access, ClusterClaim presence, scanner findings, or isolated metadata changes alone should not be represented as successful cross-tenant compromise. Coverage With Adaptation requires sufficient telemetry to evaluate whether tenant-controlled ClusterClaim activity aligns with controller-mediated ManagedCluster metadata changes, unauthorized ManagedClusterSet association, downstream policy or workload effects, or another observable violation of the affected multicluster tenant boundary.

For the September 23 Ansible Automation Platform vulnerabilities, affected-version status, automation-controller presence, scanner findings, ordinary job or workflow execution, routine project synchronization, expected credential use, normal instance-group or execution-environment activity, ordinary receptor traffic, or Kubernetes/OpenShift activity alone should not be represented as successful exploitation. Coverage With Adaptation requires sufficient product-specific identity, authorization, object ownership, request or action, credential, process, workflow, receptor, cluster, and consequential evidence to distinguish exploitation from legitimate infrastructure automation.

Coverage Qualification

This is a behavioral detection-readiness statement, not a universal Jenkins, CI/CD, deserialization, plugin, cloud, Kubernetes, CVE, KEV, victim-incident, or proof-of-concept coverage ledger. A related issue should only be considered aligned when it shares enough observable behavior with the TTD's detection model to support credible detection or detection-readiness coverage.

KEV status is an urgency, remediation-prioritization, and compromise-assessment signal, not the basis for detection coverage by itself. Coverage remains based on observable behavior aligned to the TTD's S21 through S25 detection strategy after any required platform-specific localization.

The September 16 Jenkins additions do not change this standard. Direct Behavioral Coverage applies where the durable initiating or consequential behavior maps directly to existing Jenkins-specific S25 telemetry. Coverage With Adaptation applies where the existing behavioral model remains relevant but additional plugin, credential-scope, browser, Content Security Policy, OAuth, webhook, destination, or identity context is required to identify the initiating behavior reliably.

CVE-2026-92122 through CVE-2026-92129 remain Direct Behavioral Coverage because their durable security consequence is Script Security trust bypass with potential execution in the Jenkins controller JVM. Vulnerability-specific Groovy, classpath, compile-time, or runtime mechanisms remain qualification context rather than separate detection families.

CVE-2026-92130 remains Direct Behavioral Coverage because the durable observable consequence is unauthorized access to System-scoped Jenkins credentials through Pipeline credential resolution.

CVE-2026-92131 remains Direct Behavioral Coverage because its durable observable behavior includes Pipeline-controlled traversal into Jenkins-controller filesystem locations.

CVE-2026-92137 remains Direct Behavioral Coverage because attacker-controlled configuration can create or replace arbitrary files on the Jenkins controller and may lead to controller execution.

CVE-2026-92132 through CVE-2026-92136 and CVE-2026-92138 through CVE-2026-92141 remain Coverage With Adaptation because reliable vulnerability-specific interpretation requires additional plugin-, browser-, credential-, OAuth-, webhook-, destination-, or identity-specific evidence.

The September 2 Jenkins additions do not change this standard. Direct Behavioral Coverage applies where the durable initiating or consequential behavior maps directly to existing Jenkins-specific S25 telemetry. Coverage With Adaptation applies where the existing behavioral model is relevant but additional plugin, browser, identity, API, destination, build-agent, update-site, Content Security Policy, or other product-specific context is required to identify the initiating behavior reliably.

CVE-2026-84676 remains Direct Behavioral Coverage because the observable condition is sensitive Jenkins configuration-file access resulting in plaintext token exposure, behaviors already represented through sensitive-file and credential activity. The absence of a vendor fix changes remediation and residual-risk treatment, not behavioral coverage.

CVE-2026-84674 remains Direct Behavioral Coverage because the vulnerability exposes Jenkins credential identifiers through unauthorized Jenkins requests, which maps to the current credential-activity and privileged-request model. Coverage does not imply that enumeration alone equals credential theft.

CVE-2026-84649 remains Direct Behavioral Coverage because the existing S25 model expressly includes crumb anomalies and subsequent unusual authenticated Jenkins activity. Same-site browser context and the narrower affected-version range are relevant to investigation but do not require a separate detection family.

CVE-2026-84652 remains Direct Behavioral Coverage because the durable observable outcome is reuse of an attacker-fixed session as an authenticated Jenkins user, which maps directly to the existing unusual authenticated-user context and consequential Jenkins control-plane activity.

CVE-2026-84658 remains Direct Behavioral Coverage because the material behavior is unauthorized reading of Script Security script-approval configuration through certain form submissions. CVE-2026-84658 should remain distinct from CVE-2026-84659, which is the separate Script Security permission failure allowing the global forced-sandbox setting to be disabled.

CVE-2026-84648 and CVE-2026-84665 remain Coverage With Adaptation because reliable vulnerability-specific interpretation requires browser-rendering and Content Security Policy context in addition to affected-version and plugin state. Vendor-documented CSP mitigation changes effective exposure assessment but does not change the report's behavioral coverage architecture.

TeamCity coverage requires product-specific localization and sufficient evidence to distinguish external exposure or protocol interaction from command execution and subsequent CI/CD or downstream compromise.

The JetBrains Cadence incident strengthens the evidence that CVE-2026-63077 can produce the downstream credential, data, cloud, source-code, and software-delivery consequences already represented by the TTD. JetBrains' September 3 final investigation update further changes the authoritative consequence state by establishing potential exposure of current Cadence storage containing current-user email addresses, project source code, and credentials. It does not alter CVE-2026-63077's Coverage With Adaptation classification, increase the coverage-register count, change the KEV count, or require an S21-S25 rewrite.

CVE-2026-73266 coverage requires Red Hat Multicluster Engine-specific localization and sufficient evidence to distinguish ordinary tenant or controller activity from unauthorized ClusterClaim label manipulation, controller-mediated ManagedCluster state changes, cross-tenant ManagedClusterSet association, and resulting policy or workload impact.

The September 23 Ansible Automation Platform additions do not change this standard. Coverage With Adaptation applies because the durable controller, credential, workflow, repository, execution, cloud, Kubernetes, OpenShift, and downstream infrastructure behaviors align to the existing TTD, while reliable vulnerability-specific interpretation requires automation-controller product, identity, authorization, project, inventory, workflow, credential, execution-environment, instance-group, process, receptor, external-integration, or cluster-specific context.

Executive Exposure Statement

The organization's economic exposure is highest when Jenkins controller abuse creates uncertainty around whether Jenkins administration, controller integrity, credentials, sessions, agents, jobs, plugins, artifacts, source-code workflows, cloud deployments, Kubernetes workloads, production releases, and customer-facing software delivery remain reliable. The strategic risk is not one CVE or one request path; it is the possibility that attackers can convert trusted controller authority into privileged software-delivery or infrastructure-control activity and create uncertainty over restoration of control-plane trust.

The September 16 Jenkins security release expands the represented Jenkins plugin vulnerability surface but does not change that governing behavioral model. The 20 September 16 additions consist of 11 Direct Behavioral Coverage CVEs and nine Coverage With Adaptation CVEs. Following the September 23 Ansible Automation Platform amendment and the September 24 CVE-2026-94416 addition, the current register contains 34 Direct Behavioral Coverage CVEs and 53 Coverage With Adaptation CVEs, for 87 total represented CVEs.

The September 2 Jenkins security release materially expands the number of vulnerability paths represented by this TTD but does not change that governing behavioral model.

The full September 2 advisory review confirms the existing September 2 register and requires precise interpretation of narrower affected-version boundaries for CVE-2026-84649 and CVE-2026-84653, the script-approval configuration-read behavior of CVE-2026-84658, and the vendor-documented Content Security Policy mitigation applicable to CVE-2026-84648 and CVE-2026-84665 on Jenkins 2.539 and newer and LTS 2.541.1 and newer.

Affected or previously affected TeamCity On-Premises servers create the same CI/CD trust concern where exploitation of the agent-polling protocol enables TeamCity server-process command execution. CISA's KEV confirmation, current known-ransomware-use status, and JetBrains' active-exploitation reporting increase the urgency of remediation and pre-remediation compromise review.

The JetBrains Cadence incident confirms that CVE-2026-63077 can progress from TeamCity exploitation into real downstream exposure involving personal data, historical backups, AWS IAM credentials, cloud-storage access, potential synchronized-source-code exposure, and broad credential-assurance requirements. JetBrains' September 3 final investigation update additionally establishes potential exposure of current Cadence storage containing current-user email addresses, project source code, and credentials. The incident strengthens the current executive-risk model but does not create a new detection family, change CVE-2026-63077 from Coverage With Adaptation, increase the coverage register, change the KEV count, or require an S21-S25 rewrite.

Affected Red Hat Multicluster Engine environments create a related multicluster trust concern where a lower-privileged authenticated tenant can influence a trusted controller into propagating attacker-controlled ClusterClaim labels, changing ManagedClusterSet association, and potentially causing policy or workload effects in another tenant's clusters. The business requirement is to establish that tenant isolation, cluster membership, policy state, workload state, and multicluster governance remained trustworthy.

The September 23 Red Hat Ansible Automation Platform security cohort expands the represented infrastructure-automation control-plane surface but does not change the governing behavioral model. The 30 automation-controller additions are Coverage With Adaptation, increasing the register to 34 Direct Behavioral Coverage CVEs and 52 Coverage With Adaptation CVEs, for 86 total represented CVEs. The business requirement is to establish that automation-controller identities, credentials, projects, inventories, workflows, execution environments, instance groups, controller processes, receptor paths, Kubernetes or OpenShift execution, and downstream infrastructure changes remained trustworthy.

The September 24 CVE-2026-94416 addition remains Coverage With Adaptation and increases the current register to 34 Direct Behavioral Coverage CVEs and 53 Coverage With Adaptation CVEs, for 87 total represented CVEs. The current CISA KEV-confirmed count remains one.

S40 References

Vendor / Platform Documentation

·        Red Hat Security Advisory RHSA-2026:71113 — Red Hat Ansible Automation Platform 2.6 security update — automation-controller vulnerability cohort, including the 30 CVEs represented in this TTD; affected and fixed package releases, vulnerability severity, and remediation information — hxxps[:]//access[.]redhat[.]com/errata/RHSA-2026:71113

·        Red Hat Security Advisory RHSA-2026:71115 — Red Hat Ansible Automation Platform security update — additional supported-stream remediation for applicable automation-controller vulnerabilities represented in the September 23 cohort — hxxps[:]//access[.]redhat[.]com/errata/RHSA-2026:71115

·        Red Hat Product Security — September 23, 2026 Ansible Automation Platform automation-controller CVE records — CVE-2026-75884, CVE-2026-84474, CVE-2026-84486, CVE-2026-84499, CVE-2026-84502, CVE-2026-84638, CVE-2026-84643, CVE-2026-84644, CVE-2026-84679, CVE-2026-84680, CVE-2026-84683, CVE-2026-84684, CVE-2026-84686, CVE-2026-84689, CVE-2026-84691, CVE-2026-84692, CVE-2026-84703, CVE-2026-84706, CVE-2026-84707, CVE-2026-84708, CVE-2026-84709, CVE-2026-84711, CVE-2026-84712, CVE-2026-84714, CVE-2026-84716, CVE-2026-84717, CVE-2026-84718, CVE-2026-84719, CVE-2026-84720, and CVE-2026-84724 — hxxps[:]//access[.]redhat[.]com/security/security-updates/

·        Red Hat Product Security — CVE-2026-94416 — Red Hat Ansible Automation Platform; authentication, identity, and trust prerequisites relevant to the September 24 Coverage With Adaptation registration — hxxps[:]//access[.]redhat[.]com/security/cve/CVE-2026-94416

·        Jenkins Security Advisory 2026-09-16 — Jenkins plugin vulnerabilities CVE-2026-92122 through CVE-2026-92141; Script Security sandbox bypass, classpath approval bypass, and TOCTOU behavior; Pipeline: Multibranch System-scoped credential exposure; Pipeline: Groovy Libraries path traversal; Gradle Plugin Develocity credential-bearing SSRF; GitLab Plugin credential-cache confusion; Warnings, Coverage, and OWASP Dependency-Check stored XSS; Robot Framework controller-file path traversal with potential remote code execution; Bitbucket Server Integration OAuth token hijacking; Bitbucket Push and Pull Request credential-capturing SSRF; Gitee stored XSS; Keycloak Authentication open redirect; affected plugin versions; and fixed plugin releases — hxxps[:]//www[.]jenkins[.]io/security/advisory/2026-09-16/

·        Jenkins Security Advisory 2026-09-02 — Jenkins core and plugin vulnerabilities CVE-2026-84645 through CVE-2026-84677; affected and fixed Jenkins core and plugin releases; deserialization, configuration, stored-XSS, CSRF, session, permission, SSRF, file-access, identity, command-injection, credential, and update-site behaviors; narrower affected ranges for CVE-2026-84649 and CVE-2026-84653; Content Security Policy mitigation for CVE-2026-84648 and CVE-2026-84665 on Jenkins 2.539 and newer and LTS 2.541.1 and newer; Script Security script-approval configuration disclosure for CVE-2026-84658; and Parameterized Remote Trigger Plugin no-fix status at publication — hxxps[:]//www[.]jenkins[.]io/security/advisory/2026-09-02/

·        Jenkins Security Advisory 2026-06-10 — SECURITY-3707 / CVE-2026-53435 — hxxps[:]//www[.]jenkins[.]io/security/advisory/2026-06-10/

·        Jenkins Documentation — Managing Jenkins — hxxps[:]//www[.]jenkins[.]io/doc/book/managing/

·        Jenkins Documentation — Security — hxxps[:]//www[.]jenkins[.]io/doc/book/security/

·        Jenkins Documentation — Script Console — hxxps[:]//www[.]jenkins[.]io/doc/book/managing/script-console/

·        Jenkins Documentation — Credentials — hxxps[:]//www[.]jenkins[.]io/doc/book/using/using-credentials/

·        JetBrains — Critical Security Issue Affecting TeamCity On-Premises (CVE-2026-63077) — affected TeamCity On-Premises versions, unauthenticated HTTP(S) exploitation through the agent-polling protocol, authentication-check bypass, arbitrary operating-system command execution with TeamCity server-process privileges, fixed releases 2025.11.7 and 2026.1.3, security patch plugin, and TeamCity Cloud status — hxxps[:]//blog[.]jetbrains[.]com/teamcity/2026/07/cve-2026-63077/

·        JetBrains — CVE-2026-63077: Additional Guidance Following Reports of Active Exploitation — active and attempted exploitation targeting unpatched TeamCity servers, immediate remediation guidance, fixed-version requirements, security patch plugin guidance, network-exposure reduction, and investigation guidance — hxxps[:]//blog[.]jetbrains[.]com/teamcity/2026/08/cve-2026-63077-update/

·        JetBrains — Security Incident Affecting JetBrains Cadence — confirmed exploitation of api.cadence.jetbrains.com through CVE-2026-63077; affected period August 8-24, 2026; personal-data extraction from the affected environment; compromise of a full 2024 Cadence server backup; compromise of AWS IAM users and associated credentials or secrets; access to files in JetBrains S3 buckets; potential synchronized-source-code exposure; credential-rotation guidance; containment actions; and September 3, 2026 final investigation update establishing potential exposure of current Cadence storage containing current-user email addresses, project source code, and credentials, with no additional affected users identified and the investigation concluded — hxxps[:]//blog[.]jetbrains[.]com/pycharm/2026/08/cadence-security-incident-august-2026/

·        Red Hat Product Security — CVE-2026-73266 — Multicluster Engine for Kubernetes clusterclaims-controller tenant-controlled ClusterClaim label propagation enabling unauthorized cross-tenant ManagedClusterSet association and policy or workload injection — hxxps[:]//access[.]redhat[.]com/security/cve/CVE-2026-73266

Government and Vulnerability Sources

·        NVD / CVE records — Red Hat Ansible Automation Platform automation-controller September 23, 2026 cohort: CVE-2026-75884, CVE-2026-84474, CVE-2026-84486, CVE-2026-84499, CVE-2026-84502, CVE-2026-84638, CVE-2026-84643, CVE-2026-84644, CVE-2026-84679, CVE-2026-84680, CVE-2026-84683, CVE-2026-84684, CVE-2026-84686, CVE-2026-84689, CVE-2026-84691, CVE-2026-84692, CVE-2026-84703, CVE-2026-84706, CVE-2026-84707, CVE-2026-84708, CVE-2026-84709, CVE-2026-84711, CVE-2026-84712, CVE-2026-84714, CVE-2026-84716, CVE-2026-84717, CVE-2026-84718, CVE-2026-84719, CVE-2026-84720, and CVE-2026-84724 — hxxps[:]//nvd[.]nist[.]gov/

·        CISA Known Exploited Vulnerabilities Catalog — CVE-2026-63077 added August 5, 2026 based on evidence of active exploitation; current catalog metadata marks the vulnerability as used in known ransomware campaigns; catalog reviewed for current represented KEV state — hxxps[:]//www[.]cisa[.]gov/known-exploited-vulnerabilities-catalog

·        NVD — CVE-2026-94416 — Red Hat Ansible Automation Platform — hxxps[:]//nvd[.]nist[.]gov/vuln/detail/CVE-2026-94416

·        NVD — CVE-2026-73266 — Red Hat Multicluster Engine for Kubernetes clusterclaims-controller tenant-isolation and cross-tenant ManagedClusterSet exposure — hxxps[:]//nvd[.]nist[.]gov/vuln/detail/CVE-2026-73266

·        NVD — CVE-2026-63077 — TeamCity On-Premises unauthenticated remote-code execution through the agent-polling protocol — hxxps[:]//nvd[.]nist[.]gov/vuln/detail/CVE-2026-63077

·        NVD — CVE-2026-53435 — Jenkins deserialization vulnerability — hxxps[:]//nvd[.]nist[.]gov/vuln/detail/CVE-2026-53435

Threat Technique Framework

·        MITRE ATT&CK Enterprise Matrix / Techniques Catalog — hxxps[:]//attack[.]mitre[.]org/

Security Vendor Analysis

·        GitHub Advisory Database — GHSA-g2xq-2v27-4rh3 — hxxps[:]//github[.]com/advisories/GHSA-g2xq-2v27-4rh3

·        OpenCVE — CVE-2026-53435 — hxxps[:]//app[.]opencve[.]io/cve/CVE-2026-53435

·        Rapid7 Vulnerability Database — Jenkins Advisory 2026-06-10: CVE-2026-53435: Deserialization vulnerability — hxxps[:]//www[.]rapid7[.]com/db/vulnerabilities/jenkins-2026-06-10_cve-2026-53435/

·        CVEFeed — CVE-2026-53435 — hxxps[:]//cvefeed[.]io/vuln/detail/CVE-2026-53435

Detection Platform Documentation

·        SentinelOne Documentation — hxxps[:]//docs[.]sentinelone[.]com/

·        Splunk Search Reference — hxxps[:]//docs[.]splunk[.]com/Documentation/Splunk/latest/SearchReference/WhatsInThisManual

·        Elastic Security Detection Rules Documentation — hxxps[:]//www[.]elastic[.]co/guide/en/security/current/rules-ui-management[.]html

·        IBM QRadar Documentation — hxxps[:]//www[.]ibm[.]com/docs/en/qradar-common

·        Sigma Rule Specification — hxxps[:]//sigmahq[.]io/docs/basics/rules[.]html

·        AWS WAF Documentation — hxxps[:]//docs[.]aws[.]amazon[.]com/waf/

·        Azure Monitor Logs Documentation — hxxps[:]//learn[.]microsoft[.]com/azure/azure-monitor/logs/

·        Google Cloud Logging Documentation — hxxps[:]//cloud[.]google[.]com/logging/docs

Previous
Previous

[TTD] PLC Configuration Manipulation and Water/Wastewater Process-Control Disruption

Next
Next

[EXP] KVM Guest-to-Host Escape and Multi-Tenant Virtualization Boundary Compromise Risk