CVE-2026-70426, a critical deserialization bypass allowing remote code execution on the Jenkins controller, is fixed only in 2.576 and LTS 2.568.2. Under Jenkins's rolling-LTS policy, every older LTS line — 2.555 and back — will never receive this fix.
The part the advisory doesn't spell out: "and earlier" means forever
| LTS line | Superseded (per lifecycle data) | Fix for CVE-2026-70426? |
|---|---|---|
| 2.568 | Current baseline | Yes — 2.568.2 |
| 2.555 | July 2026 | Never |
| 2.541 | April 2026 | Never |
| 2.528 | January 2026 | Never |
| 2.516 and older | 2025 and earlier | Never |
What's covered
- What CVE-2026-70426 actually is
- The part the advisory doesn't spell out: "and earlier" means forever
- The three moves
- The lesson, restated
Full guide with every version, risk scores, and live updates: https://endoflife.ai/article-jenkins-cve-2026-70426
Top comments (0)