09/05/2026, 12.45

Critical CI/CD and Infrastructure Flaws: New Security Alerts

New security alerts highlight critical vulnerabilities in Jenkins, ASUS, and Plesk, alongside Chrome zero-days. Learn the risks for global business infrastructure.
Key points
  • Jenkins faces six high-severity vulnerabilities affecting CI/CD pipelines and automation.
  • ASUS Control Center reports a critical flaw allowing authentication bypass and privilege elevation.
  • Plesk for Linux suffers from a high-severity arbitrary code execution vulnerability.
  • Google Chrome has patched 12 vulnerabilities, including two critical zero-days already exploited.

The modern enterprise tech stack is only as strong as its most overlooked dependency. Recent security bulletins issued by the Italian National Cybersecurity Agency (ACN) highlight a dangerous convergence of vulnerabilities across the very tools that power the digital economy: continuous integration pipelines, server management software, and the primary gateway to the web, the browser.

For business owners and CTOs, these alerts are not merely technical footnotes. They represent systemic risks to the software supply chain and the internal administrative layers of corporate infrastructure. When vulnerabilities strike CI/CD tools or server control panels, the potential for a full-scale breach increases exponentially, as these systems often hold the keys to the entire production environment.

The Jenkins Crisis and CI/CD Pipeline Risks

One of the most concerning developments involves Jenkins, the open-source cornerstone of automation for integration and continuous delivery. According to the ACN alert, multiple vulnerabilities have been identified, with six categorized as high severity. These flaws encompass a wide range of attack vectors, including Remote Code Execution (RCE), security restrictions bypass, tampering, and spoofing.

The affected versions include Jenkins 2.x (version 2.579 and earlier) and LTS 2.x (version LTS 2.568.2 and earlier). Because Jenkins sits at the heart of the development lifecycle, an attacker gaining access through these vulnerabilities could potentially inject malicious code directly into a company's software products before they ever reach the customer. This makes the systemic impact high, as it threatens the integrity of the entire delivery pipeline.

Critical Access Failures in ASUS Control Center

While Jenkins threatens the software pipeline, ASUS has faced a critical security failure in its Control Center. The vulnerability, tracked as CVE-2026-75754, is classified as critical due to its ability to facilitate authentication bypass and elevation of privilege. In practical terms, this means an unauthorized actor could potentially circumvent security checks to gain administrative control over the system.

The flaw affects ASUS Control Center version 4.0.0.2 and all previous versions. For enterprises utilizing ASUS hardware for server management, this represents a significant hole in the perimeter. The ability to bypass authentication allows for tampering and unauthorized access to sensitive hardware configurations, potentially leading to total system compromise.

Arbitrary Code Execution in Plesk Server Management

Server administration tools are high-value targets because they provide a centralized point of control for web hosting environments. Plesk for Linux has recently been flagged for a high-severity vulnerability (CVE-2026-67397) that allows for arbitrary code execution. This flaw impacts version 18.0.79.9 and earlier, as well as versions from 18.0.80 to 18.0.80.5.

If exploited, a malicious actor could run unauthorized commands on the affected server, leading to data theft, website defacement, or the installation of ransomware. The systemic impact is rated as medium, but for a business relying on Plesk to manage its web presence, the operational risk is absolute.

Chrome Zero-Days and the Browser Attack Surface

Beyond the backend infrastructure, the primary interface for every employee—the web browser—remains a constant battleground. Google has released an urgent update for Chrome to address 12 new security vulnerabilities. Most alarming is the discovery of two critical zero-day vulnerabilities that were already being exploited in the wild before a patch was available.

In addition to the zero-days, seven other vulnerabilities were rated as high severity. Because the browser is the primary tool for accessing SaaS platforms, cloud consoles, and corporate emails, a browser-level exploit can be used to steal session cookies, capture keystrokes, or deliver malware to the endpoint, bypassing many traditional network defenses.

Mitigation Strategies for Technical Leadership

The common thread across these disparate alerts is the necessity of immediate patching. The vendors for Jenkins, ASUS, and Plesk have all released updates to resolve these flaws. For the modern entrepreneur, the challenge is not just the existence of the patch, but the speed of deployment across a fragmented infrastructure.

The risk is rarely the vulnerability itself, but the window of time between the public disclosure of the flaw and the application of the fix.

Organizations should prioritize their updates based on the systemic impact. The Jenkins and ASUS vulnerabilities should be treated as top priorities due to their potential to compromise the entire production environment or grant administrative hardware access. Chrome updates, while critical, are often handled by automated browser updates, but IT managers must ensure that legacy versions are not lingering on corporate machines.

Global Implications for US and UK Enterprises

For businesses operating in the USA and UK, these vulnerabilities intersect with an increasingly stringent regulatory landscape regarding cybersecurity resilience. In the United Kingdom, the push toward the Product Security and Telecommunications Infrastructure (PSTI) Act emphasizes the need for manufacturers to ensure devices are secure by design and up-to-date.

In the United States, the focus on software supply chain security—driven by Executive Orders on Improving the Nation's Cybersecurity—makes the Jenkins vulnerability particularly relevant. US firms are under increasing pressure to maintain a Software Bill of Materials (SBOM) to track exactly which versions of open-source tools like Jenkins are embedded in their workflows.

Failure to patch these known vulnerabilities can lead to more than just technical downtime. Under various data protection frameworks, including the UK GDPR and various US state laws (such as CCPA), a breach resulting from a failure to apply a known, critical security patch can be viewed as a failure to implement reasonable security measures, potentially leading to significant legal liabilities and regulatory fines.

FAQ

Which versions of Jenkins are most at risk?

Jenkins 2.x (version 2.579 and earlier) and LTS 2.x (version LTS 2.568.2 and earlier) are affected by six high-severity vulnerabilities.

What is the main risk associated with the ASUS Control Center flaw?

The critical vulnerability CVE-2026-75754 allows for authentication bypass and elevation of privilege, meaning attackers could gain unauthorized administrative access.

How should a company handle the Google Chrome zero-day?

Users should update Chrome to the latest version immediately, as two of the patched vulnerabilities were already being exploited by attackers.

What does arbitrary code execution mean in the context of Plesk?

It means a malicious user could run their own commands on the server, potentially taking full control of the web hosting environment.


Sources: Acn (7) ·

Hai una domanda su questo dossier?

Scrivila qui: Susanna, l assistente AI di glacom, ti risponde via email con un approfondimento gratuito.

Nessuna consulenza personalizzata (finanziaria, legale o medica): solo informazione e fonti. Email usata solo per rispondere.

oppure scrivile su: WhatsApp · Telegram · SimpleX · Delta Chat · Email

Printable version
CLOSE X
Share this story
See also
Trezor Supply Chain Breach: 80,000+ Customers' Data Exposed
Trezor reveals a massive data leak via shipping partner ShipMonk, exposing 80,000+ customers to phishing and physical risks. Learn the impact and risk…
05/09/2026 21:00
The Ted Backdoor: How State-Sponsored Actors Trojanized HAProxy
North Korean APTs targeted South Korean automotive and media firms using a stealthy HAProxy backdoor called Ted to intercept traffic and execute comma…
04/09/2026 21:01
ASCII Smuggling: How Invisible Unicode Evades Email Security
Hackers are repurposing AI prompt-injection techniques to hide phishing lures in millions of emails, bypassing filters using invisible Unicode charact…
04/09/2026 19:44
Integer Overflow Risks: The Hidden Threat to Enterprise Software
Discover how integer overflow vulnerabilities compromise software security and what global business leaders must do to protect their digital infrastru…
04/09/2026 19:39
LLMjacking: The New Cloud Threat Monetizing Premium AI Models
Attackers are using leaked AWS IAM keys to hijack premium AI models, billing victims over 0k daily. Learn how LLMjacking works and how to secure yo…
04/09/2026 19:33


Newsletter

Subscribe to glacom updates or change your preferences

Subscribe now

ISCRIVITI A GLACOM.NEWS

I dossier su AI, tech e business che contano, nella tua email. Gratis.