Critical CI/CD and Infrastructure Flaws: New Security Alerts

- Jenkins faces six high-severity vulnerabilities affecting CI/CD pipelines and automation.
- ASUS Control Center reports a critical flaw allowing authentication bypass and privilege elevation.
- Plesk for Linux suffers from a high-severity arbitrary code execution vulnerability.
- Google Chrome has patched 12 vulnerabilities, including two critical zero-days already exploited.
The modern enterprise tech stack is only as strong as its most overlooked dependency. Recent security bulletins issued by the Italian National Cybersecurity Agency (ACN) highlight a dangerous convergence of vulnerabilities across the very tools that power the digital economy: continuous integration pipelines, server management software, and the primary gateway to the web, the browser.
For business owners and CTOs, these alerts are not merely technical footnotes. They represent systemic risks to the software supply chain and the internal administrative layers of corporate infrastructure. When vulnerabilities strike CI/CD tools or server control panels, the potential for a full-scale breach increases exponentially, as these systems often hold the keys to the entire production environment.
The Jenkins Crisis and CI/CD Pipeline Risks
One of the most concerning developments involves Jenkins, the open-source cornerstone of automation for integration and continuous delivery. According to the ACN alert, multiple vulnerabilities have been identified, with six categorized as high severity. These flaws encompass a wide range of attack vectors, including Remote Code Execution (RCE), security restrictions bypass, tampering, and spoofing.
The affected versions include Jenkins 2.x (version 2.579 and earlier) and LTS 2.x (version LTS 2.568.2 and earlier). Because Jenkins sits at the heart of the development lifecycle, an attacker gaining access through these vulnerabilities could potentially inject malicious code directly into a company's software products before they ever reach the customer. This makes the systemic impact high, as it threatens the integrity of the entire delivery pipeline.
Critical Access Failures in ASUS Control Center
While Jenkins threatens the software pipeline, ASUS has faced a critical security failure in its Control Center. The vulnerability, tracked as CVE-2026-75754, is classified as critical due to its ability to facilitate authentication bypass and elevation of privilege. In practical terms, this means an unauthorized actor could potentially circumvent security checks to gain administrative control over the system.
The flaw affects ASUS Control Center version 4.0.0.2 and all previous versions. For enterprises utilizing ASUS hardware for server management, this represents a significant hole in the perimeter. The ability to bypass authentication allows for tampering and unauthorized access to sensitive hardware configurations, potentially leading to total system compromise.
Arbitrary Code Execution in Plesk Server Management
Server administration tools are high-value targets because they provide a centralized point of control for web hosting environments. Plesk for Linux has recently been flagged for a high-severity vulnerability (CVE-2026-67397) that allows for arbitrary code execution. This flaw impacts version 18.0.79.9 and earlier, as well as versions from 18.0.80 to 18.0.80.5.
If exploited, a malicious actor could run unauthorized commands on the affected server, leading to data theft, website defacement, or the installation of ransomware. The systemic impact is rated as medium, but for a business relying on Plesk to manage its web presence, the operational risk is absolute.
Chrome Zero-Days and the Browser Attack Surface
Beyond the backend infrastructure, the primary interface for every employee—the web browser—remains a constant battleground. Google has released an urgent update for Chrome to address 12 new security vulnerabilities. Most alarming is the discovery of two critical zero-day vulnerabilities that were already being exploited in the wild before a patch was available.
In addition to the zero-days, seven other vulnerabilities were rated as high severity. Because the browser is the primary tool for accessing SaaS platforms, cloud consoles, and corporate emails, a browser-level exploit can be used to steal session cookies, capture keystrokes, or deliver malware to the endpoint, bypassing many traditional network defenses.
Mitigation Strategies for Technical Leadership
The common thread across these disparate alerts is the necessity of immediate patching. The vendors for Jenkins, ASUS, and Plesk have all released updates to resolve these flaws. For the modern entrepreneur, the challenge is not just the existence of the patch, but the speed of deployment across a fragmented infrastructure.
The risk is rarely the vulnerability itself, but the window of time between the public disclosure of the flaw and the application of the fix.
Organizations should prioritize their updates based on the systemic impact. The Jenkins and ASUS vulnerabilities should be treated as top priorities due to their potential to compromise the entire production environment or grant administrative hardware access. Chrome updates, while critical, are often handled by automated browser updates, but IT managers must ensure that legacy versions are not lingering on corporate machines.
Global Implications for US and UK Enterprises
For businesses operating in the USA and UK, these vulnerabilities intersect with an increasingly stringent regulatory landscape regarding cybersecurity resilience. In the United Kingdom, the push toward the Product Security and Telecommunications Infrastructure (PSTI) Act emphasizes the need for manufacturers to ensure devices are secure by design and up-to-date.
In the United States, the focus on software supply chain security—driven by Executive Orders on Improving the Nation's Cybersecurity—makes the Jenkins vulnerability particularly relevant. US firms are under increasing pressure to maintain a Software Bill of Materials (SBOM) to track exactly which versions of open-source tools like Jenkins are embedded in their workflows.
Failure to patch these known vulnerabilities can lead to more than just technical downtime. Under various data protection frameworks, including the UK GDPR and various US state laws (such as CCPA), a breach resulting from a failure to apply a known, critical security patch can be viewed as a failure to implement reasonable security measures, potentially leading to significant legal liabilities and regulatory fines.
FAQ
Which versions of Jenkins are most at risk?
Jenkins 2.x (version 2.579 and earlier) and LTS 2.x (version LTS 2.568.2 and earlier) are affected by six high-severity vulnerabilities.
What is the main risk associated with the ASUS Control Center flaw?
The critical vulnerability CVE-2026-75754 allows for authentication bypass and elevation of privilege, meaning attackers could gain unauthorized administrative access.
How should a company handle the Google Chrome zero-day?
Users should update Chrome to the latest version immediately, as two of the patched vulnerabilities were already being exploited by attackers.
What does arbitrary code execution mean in the context of Plesk?
It means a malicious user could run their own commands on the server, potentially taking full control of the web hosting environment.
Sources: Acn (7) ·
Scrivila qui: Susanna, l assistente AI di glacom, ti risponde via email con un approfondimento gratuito.
Nessuna consulenza personalizzata (finanziaria, legale o medica): solo informazione e fonti. Email usata solo per rispondere.
oppure scrivile su: WhatsApp · Telegram · SimpleX · Delta Chat · Email



