The Jenkins project will publish a security advisory for Jenkins plugins on Wednesday, April 12. The highest severity is 'High' and affects plugins installed on less than 1% of known instances. The most popular included plugins are installed on between 10% and 25% of known instances and have 'Medium' severity issues. The advisory includes issues that will be published without a fix as outlined at
https://www.jenkins.io/security/plugins/
This affects only Jenkins plugins, there will be no corresponding security update for Jenkins itself.