Security-control, CI/CD and trusted-tool weaknesses expand enterprise attack surface
Jenkins' September 2 advisory disclosed crafted-XML RCE paths, token exposure, XSS and agent takeover, while new reporting reinforces living-off-the-land risks involving PowerShell, WMI, credential abuse and managed-service-provider access. ServiceNow, Entra ID, Splunk and other enterprise-platform issues remain remediation priorities; the reported CrowdStrike Falcon privilege-escalation issue still requires exploitability and exploitation verification.
Sources (2)
Updated Sep 9, 2026