DEV Community

endoflife-ai
endoflife-ai

Posted on • Originally published at endoflife.ai

Every Jenkins LTS Except the Newest Is Now Permanently Vulnerable — CVE-2026-70426

CVE-2026-70426, a critical deserialization bypass allowing remote code execution on the Jenkins controller, is fixed only in 2.576 and LTS 2.568.2. Under Jenkins's rolling-LTS policy, every older LTS line — 2.555 and back — will never receive this fix.

The part the advisory doesn't spell out: "and earlier" means forever

LTS line Superseded (per lifecycle data) Fix for CVE-2026-70426?
2.568 Current baseline Yes — 2.568.2
2.555 July 2026 Never
2.541 April 2026 Never
2.528 January 2026 Never
2.516 and older 2025 and earlier Never

What's covered

  • What CVE-2026-70426 actually is
  • The part the advisory doesn't spell out: "and earlier" means forever
  • The three moves
  • The lesson, restated

Full guide with every version, risk scores, and live updates: https://endoflife.ai/article-jenkins-cve-2026-70426

Top comments (0)