<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Jenkins</title><description>Actively exploited vulnerabilities affecting Jenkins products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/jenkins.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2017-1000353 — Jenkins Remote Code Execution Vulnerability</title><link>https://wildfortech.com/security#CVE-2017-1000353</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2017-1000353</guid><description>This Jenkins vulnerability allows remote attackers to execute arbitrary code by exploiting the CLI&apos;s deserialization handling. An attacker can send a specially crafted serialized Java SignedObject to the remoting-based Jenkins CLI, which then deserializes it through a new ObjectInputStream, completely sidestepping Jenkins&apos; existing blocklist protections. Because Jenkins is widely used in CI/CD pipelines, successful exploitation could give attackers full control over build infrastructure and potentially the broader software supply chain.</description><pubDate>Thu, 02 Oct 2025 00:00:00 GMT</pubDate><category>Jenkins</category><category>Jenkins</category></item></channel></rss>