The following Jenkins plugin updates contain fixes for security vulnerabilities:
* Active Directory Plugin 2.41.2
* Bitbucket Push and Pull Request Plugin 3.3.9
* Contrast Continuous Application Security Plugin 3.12
* EC2 Fleet Plugin 4.2.3.540.va_6eedb_7b_c112
* External Workspace Manager Plugin 1.4.0
* Git client Plugin 6.6.1
* Git Parameter Plugin 462.463.v496a_59f698e5
* Gitee Plugin 1292.v2559f2f3f2c0
* GitHub Branch Source Plugin 1967.1970.vd86979736546
* Job Configuration History Plugin 1367.vc8fa_b_15101dc
* MCP Server Plugin 0.178.vffe5a_e770f3b_
* Pipeline: Groovy Plugin 4331.4333.v50a_b_076c5199
* Priority Sorter Plugin 936.937.v5581d0b_2ccb_a_
* Script Security Plugin 1402.1405.vc96e74964250
Additionally, we announce unresolved security issues in the following plugins:
* Assembla Plugin
* FitNesse Plugin
* OWASP ZAP Plugin
* Zowe zDevOps Plugin
Please see the advisory for more information:
https://www.jenkins.io/security/advisory/2026-06-24/