Newly released CVEs across every platform — sleek to read, verbose on demand, and served raw as markdown for AI and agent ingestion. Severity reads as depth: the deeper the contact, the graver the threat.
Depth = severity + exploitation
CVE-2026-57301High· 8.8Jenkins OWASP ZAP Plugin: Builds executed on the Jenkins controller can lead to RCE
CVE-2026-57303High· 7.1Jenkins Assembla Plugin has an XXE vulnerability
CVE-2026-57302Medium· 4.3Jenkins FitNesse Plugin stores passwords unencrypted
CVE-2026-57305Medium· 5.4Jenkins Assembla Plugin has a cross-site request forgery (CSRF) vulnerability
CVE-2026-57304Medium· 5.4Jenkins Assembla Plugin has a missing permission check
CVE-2026-57296High· 8.8Jenkins External Workspace Manager Plugin has a path traversal vulnerability
CVE-2026-57288Low· 3.7Jenkins Active Directory Plugin has an LDAP injection vulnerability
CVE-2026-57293Medium· 4.3Jenkins Gitee Plugin has an incorrect permission check that allows enumerating credentials IDs
CVE-2026-57292Medium· 5.4Jenkins Gitee Plugin has a cross-site request forgery vulnerability
CVE-2026-57290Medium· 4.3Jenkins Priority Sorter Plugin has a CSRF vulnerability
CVE-2026-57298Medium· 5.4Jenkins Contrast Continuous Application Security Plugin has a CSRF vulnerability
CVE-2026-57291Medium· 5.4Jenkins Gitee Plugin missing permission checks
CVE-2026-57280High· 8.8Jenkins Script Security Plugin sandbox bypass vulnerability
CVE-2026-57281High· 7.5Jenkins Script Security Plugin has a script security bypass vulnerability
CVE-2026-57286Medium· 4.3Jenkins Git Parameter Plugin has a missing permission check that allows listing SCM branch and tag names
CVE-2026-57282Medium· 5.0Jenkins Git client Plugin has an OS command injection vulnerability on agents
CVE-2026-57285Medium· 4.3Jenkins GitHub Branch Source Plugin has missing permission check that allows enumerating GitHub Enterprise server URLs
CVE-2026-57287Medium· 4.3Jenkins Job Configuration History Plugin doesn't redact encrypted values of secrets in job and agent configurations
A summary of everything that shipped over the last two weeks — the whole corpus is open, agents get change feeds, alias resolution and EPSS movers, and the data now includes CVE.org, vendor CSAF, aggregated exploits and per-source scores.
A step-by-step guide to plugging VulnSea into automated and agentic workflows — poll the delta, triage without burning tokens, match an SBOM, and let an MCP-native model do the reasoning.
CVE and 0day intelligence that reads like an instrument — built for analysts and AI agents alike. Here's what it does and where it's going.