# CloudBees CI release notes

If you skip versions when you upgrade, refer to previous versions of the release notes for any relevant known issues or upgrade notes. The [CloudBees supported platforms](/docs/cloudbees-common/latest/supported-platforms/) and [CloudBees maintenance lifecycle policies](/docs/cloudbees-common/latest/maintenance-lifecycle#_cloudbees_ci) pages contain additional information about what is supported in this release.

Latest 2.568.3.37913 Security release
-------------------------------------

Released: September 16, 2026

### Modern cloud platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms/2.568.3.37913) [Plugins list - Managed controller](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-managed-controller/2.568.3.37913) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-operations-center/2.568.3.37913)

### Traditional platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/traditional-platforms/2.568.3.37913) [Plugins list - Client controller](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-client-controller/2.568.3.37913) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-operations-center/2.568.3.37913)

2.568.3.37907 Security release
------------------------------

Released: September 2, 2026

### Modern cloud platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms/2.568.3.37907) [Plugins list - Managed controller](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-managed-controller/2.568.3.37907) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-operations-center/2.568.3.37907)

### Traditional platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/traditional-platforms/2.568.3.37907) [Plugins list - Client controller](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-client-controller/2.568.3.37907) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-operations-center/2.568.3.37907)

2.568.2.37664 Security release
------------------------------

Released: August 5, 2026

### Modern cloud platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms/2.568.2.37664) [Plugins list - Managed controller](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-managed-controller/2.568.2.37664) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-operations-center/2.568.2.37664)

### Traditional platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/traditional-platforms/2.568.2.37664) [Plugins list - Client controller](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-client-controller/2.568.2.37664) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-operations-center/2.568.2.37664)

2.568.1.37445
-------------

Released: July 8, 2026

Hazelcast upgrade from 5.6.0 to 5.7.0

The Hazelcast library used for peer-to-peer communications in High Availability (HA) controllers has been upgraded from version 5.6.0 to 5.7.0. Since Hazelcast Community Edition does not support members of different minor versions sharing a cluster, a regular rolling upgrade across this change is not possible. If you are running an HA controller on any previous version, the upgrade should be automatic, although there will be a temporary outage, similar to upgrading a non-HA controller.

Blue Ocean end-of-life for CloudBees CI on traditional platforms

Starting with this release, Blue Ocean has reached end-of-life (EOL) and is no longer supported. Blue Ocean will not receive future updates, security patches, or technical support and has been removed from the CloudBees Assurance Program (CAP).

What this means for you:

*   Blue Ocean may continue to work, but is no longer supported by CloudBees.
    
*   Technical support for Blue Ocean is no longer available.
    

For Pipeline visualization, CloudBees recommends [CloudBees Pipeline Explorer](/docs/cloudbees-ci/latest/pipelines/cloudbees-pipeline-explorer-plugin) as an alternative. If you have questions or need assistance, please contact [CloudBees Support](https://support.cloudbees.com/).

Blue Ocean and team controllers end-of-life for CloudBees CI on modern cloud platforms

Starting with this release, Blue Ocean and Team controllers have reached end-of-life (EOL) and are no longer supported. Blue Ocean and Team controllers will not receive future updates, security patches, or technical support and have been removed from the CloudBees Assurance Program (CAP).

What this means for you:

*   Team controllers no longer function.
    
*   Blue Ocean may continue to work, but is no longer supported by CloudBees.
    
*   Technical support for Blue Ocean and Team controllers is no longer available.
    

CloudBees strongly encourages all customers to complete their migration away from Team controllers to ensure uninterrupted service. For detailed migration guidance, please refer to [Migrate team controllers to managed controllers using Move/Copy/Promote](/d/kb-1781204168) or [In-place conversion of team controllers to managed controllers](/d/kb-1764250214). If you have questions or need assistance, please contact [CloudBees Support](https://support.cloudbees.com/).

### Modern cloud platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms/2.568.1.37445) [Plugins list - Managed controller](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-managed-controller/2.568.1.37445) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-operations-center/2.568.1.37445)

### Traditional platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/traditional-platforms/2.568.1.37445) [Plugins list - Client controller](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-client-controller/2.568.1.37445) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-operations-center/2.568.1.37445)

2.555.3.36985 Security release
------------------------------

Released: June 24, 2026

### Modern cloud platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms/2.555.3.36985) [Plugins list - Managed controller](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-managed-controller/2.555.3.36985) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-operations-center/2.555.3.36985)

### Traditional platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/traditional-platforms/2.555.3.36985) [Plugins list - Client controller](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-client-controller/2.555.3.36985) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-operations-center/2.555.3.36985)

2.555.3.36983 Security release
------------------------------

Released: June 10, 2026

### Modern cloud platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms/2.555.3.36983) [Plugins list - Managed controller](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-managed-controller/2.555.3.36983) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-operations-center/2.555.3.36983)

### Traditional platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/traditional-platforms/2.555.3.36983) [Plugins list - Client controller](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-client-controller/2.555.3.36983) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-operations-center/2.555.3.36983)

2.555.2.36756 Security release
------------------------------

Released: May 27, 2026

### Modern cloud platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms/2.555.2.36756) [Plugins list - Managed controller](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-managed-controller/2.555.2.36756) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-operations-center/2.555.2.36756)

### Traditional platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/traditional-platforms/2.555.2.36756) [Plugins list - Client controller](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-client-controller/2.555.2.36756) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-operations-center/2.555.2.36756)

2.555.2.36753
-------------

Released: May 13, 2026

### Modern cloud platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms/2.555.2.36753) [Plugins list - Managed controller](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-managed-controller/2.555.2.36753) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-operations-center/2.555.2.36753)

### Traditional platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/traditional-platforms/2.555.2.36753) [Plugins list - Client controller](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-client-controller/2.555.2.36753) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-operations-center/2.555.2.36753)

2.555.1.36488 Security release
------------------------------

Released: April 29, 2026

### Modern cloud platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms/2.555.1.36488) [Plugins list - Managed controller](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-managed-controller/2.555.1.36488) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-operations-center/2.555.1.36488)

### Traditional platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/traditional-platforms/2.555.1.36488) [Plugins list - Client controller](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-client-controller/2.555.1.36488) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-operations-center/2.555.1.36488)

2.555.1.36485
-------------

Released: April 15, 2026

Java 17 is no longer supported and Java 21 is now required

As of the CloudBees CI 2.555.1.36485 release, Java 17 is no longer supported, and you must migrate to Java 21. An administrative monitor is available to notify you if either the operations center or any connected controllers are running with Java 17. For information on migrating from Java 17 to Java 21, refer to:

*   [Migrate to Java 21 - CloudBees CI on traditional platforms](/docs/cloudbees-ci/latest/traditional-upgrading-guide/java-21-migration-traditional).
    
*   [Migrate to Java 21 - CloudBees CI on modern cloud platforms](/docs/cloudbees-ci/latest/cloud-upgrade-guide/java-21-migration-cloud).
    

If you have any concerns or questions, please contact [CloudBees Support](https://support.cloudbees.com).

New health check endpoint now enforced on managed controllers

CloudBees CI 2.504.1.6 introduced a new health check endpoint for controllers and added an option in the managed controller configuration to enable this endpoint. Since CloudBees CI 2.492.3.5 (the last release without the new endpoint) is no longer supported, the option to enable the new endpoint has been removed. Managed controller provisioning now always uses the new `/health/` endpoint, sometimes with a probe query parameter to fine-tune behavior, instead of the older `/whoAmI/api/json?tree=authenticated` endpoint. The new `/health/` endpoint provides richer functionality, especially for High Availability (HA) controllers.

The Configuration as Code option `useNewHealthCheck: true` in the operations center `items.yaml` file is also no longer supported.

Managed controllers running an older version should not be reprovisioned by an updated operations center until they are upgraded to a supported version, as their probes will fail and the pod will not become ready. Managed controllers running CloudBees CI version 2.492.3.5 or earlier are not supported under the CloudBees CI maintenance lifecycle policy and may not work correctly with the new health check endpoint. According to the CloudBees CI version skew policy, running this version of the operations center with an older managed controller is not supported until the managed controller has been updated.

Client controllers are not affected. If your load balancer allows you to configure a health check endpoint, `/health/` is recommended.

Breaking change: Removed deprecated CSRF proxy compatibility settings

Jenkins 2.543 removed the client IP address from CSRF crumb validation. As a result, the `crumbIssuerProxyCompatibility` system property (automatically set on HA controllers), the `excludeClientIPFromCrumb` Configuration as Code (CasC) attribute, and the `OperationsCenter.CSRF.ProxyCompatibility` Helm value may cause the CloudBees CI instance to fail on startup. CloudBees recommends that you remove these configurations.

The `externalTrafficPolicy=Local` workaround on ingress-nginx, which was previously recommended to preserve client IP addresses for crumb validation, is also no longer necessary.

### Modern cloud platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms/2.555.1.36485) [Plugins list - Managed controller](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-managed-controller/2.555.1.36485) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-operations-center/2.555.1.36485)

### Traditional platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/traditional-platforms/2.555.1.36485) [Plugins list - Client controller](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-client-controller/2.555.1.36485) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-operations-center/2.555.1.36485)

2.541.3.36069
-------------

Released: March 24, 2026

### Modern cloud platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms/2.541.3.36069) [Plugins list - Managed controller](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-managed-controller/2.541.3.36069) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-operations-center/2.541.3.36069)

### Traditional platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/traditional-platforms/2.541.3.36069) [Plugins list - Client controller](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-client-controller/2.541.3.36069) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-operations-center/2.541.3.36069)

2.541.3.36065 Security release
------------------------------

Released: March 18, 2026

Standardized authentication to hibernation monitor from managed controllers

New managed controllers now authenticate to the hibernation monitor using the same Kubernetes service account system as other microservices. Existing managed controllers may need to be reprovisioned to pick up the new token mount. Older managed controllers can continue using the previous authentication system until they are no longer supported in one year.

### Modern cloud platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms/2.541.3.36065) [Plugins list - Managed controller](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-managed-controller/2.541.3.36065) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-operations-center/2.541.3.36065)

### Traditional platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/traditional-platforms/2.541.3.36065) [Plugins list - Client controller](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-client-controller/2.541.3.36065) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-operations-center/2.541.3.36065)

2.541.2.35785 Security release
------------------------------

Released: February 18, 2026

### Modern cloud platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms/2.541.2.35785) [Plugins list - Managed controller](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-managed-controller/2.541.2.35785) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-operations-center/2.541.2.35785)

### Traditional platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/traditional-platforms/2.541.2.35785) [Plugins list - Client controller](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-client-controller/2.541.2.35785) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-operations-center/2.541.2.35785)

2.541.1.35570
-------------

Released: January 22, 2026

Blue Ocean and team controllers end-of-life

Starting with the July 2026 CloudBees CI on modern cloud platforms release, Blue Ocean and Team controllers will reach end-of-life (EOL) and will no longer be supported. After this date, Blue Ocean and Team controllers will not receive updates, security patches, or technical support and will be removed from the CloudBees Assurance Program (CAP).

What this means for you:

*   Team controllers will cease to function starting with the July 2026 release.
    
*   Blue Ocean may continue to work, but is no longer supported by CloudBees.
    
*   No further updates or security patches will be provided.
    
*   Technical support for Blue Ocean and Team controllers will no longer be available.
    

CloudBees strongly encourages all customers to complete their migration away from Team controllers before the EOL date to ensure uninterrupted service. For detailed migration guidance, please refer to [In-place conversion of team controllers to managed controllers](/d/kb-1764250214). If you have questions or need assistance, please contact [CloudBees Support](https://support.cloudbees.com/).

Plugin release notes no longer provided; updates included in product release notes

Starting with CloudBees CI 2.541.1.35570, all plugin changes and updates are now included directly in the [CloudBees CI release notes](/docs/release-notes/latest/cloudbees-ci/). This streamlines release information and ensures you have a single source for all product and plugin updates. As a result, separate plugin release notes are no longer generated, and all previously available plugin-specific release notes have been removed.

### Modern cloud platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms/2.541.1.35570) [Plugins list - Managed controller](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-managed-controller/2.541.1.35570) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-operations-center/2.541.1.35570)

### Traditional platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/traditional-platforms/2.541.1.35570) [Plugins list - Client controller](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-client-controller/2.541.1.35570) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-operations-center/2.541.1.35570)

2.528.3.35200 Security release
------------------------------

Released: December 10, 2025

### Modern cloud platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms/2.528.3.35200) [Plugins list - Managed controller](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-managed-controller/2.528.3.35200) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-operations-center/2.528.3.35200)

### Traditional platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/traditional-platforms/2.528.3.35200) [Plugins list - Client controller](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-client-controller/2.528.3.35200) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-operations-center/2.528.3.35200)

2.528.2.34846 Security release
------------------------------

Released: November 12, 2025

Container images updated from UBI 8 to UBI 9

The following images now use UBI 9:

For CloudBees CI on modern cloud platforms on Kubernetes:

*   `cloudbees/cloudbees-cloud-core-oc`
    
*   `cloudbees/cloudbees-core-mm`
    
*   `cloudbees/cloudbees-core-agent`
    

For CloudBees CI on traditional platforms running in Docker:

*   `cloudbees/cloudbees-core-oc`
    
*   `cloudbees/cloudbees-core-cm`
    

Removed `sidecarinjector` subchart

The `cloudbees-sidecar-injector` subchart is no longer included with the CloudBees CI chart. Users should install a recent version of this chart separately and follow the instructions provided in its documentation.

Hazelcast upgrade in High Availability (HA) controllers

The Hazelcast library used in High Availability (HA) controllers has been upgraded from version 5.5.0 to 5.6.0. This upgrade does not support rolling upgrades. If you are running an High Availability (HA) controller on any previous version, the upgrade to this (or a later) version should be automatic, but it will cause a temporary outage of the controller. This outage is similar to a simple restart of a non-High Availability (HA) controller.

Azure storage for backup jobs failed when using Instance Configuration

Previously, there was a problem setting up Azure Storage for backups when using Instance Configuration (Azure Managed Identity as credentials to access the storage account). To resolve this, the plugin has been migrated to use the newer Azure SDK, which fixes the issue.

If you are not using Azure storage for backups, or if you are using Azure with explicit credentials (using the **Provide account configuration** option), you are not affected.

If you are using **Use Azure Instance configuration** option, you must update your backup job configuration to explicitly set the Storage Account name.

Breaking change: CloudBees CI now supports Kubernetes 1.34 and requires Kubernetes 1.30+ and Red Hat OpenShift 4.17+

Starting with this release, CloudBees CI now supports Kubernetes 1.34 and requires Kubernetes 1.30 or later.

Support for older Kubernetes versions (1.29 and earlier) and Red Hat OpenShift 4.16 has been removed. If you are using Kubernetes 1.29 or earlier, you must upgrade to at least Kubernetes 1.30 and Red Hat OpenShift 4.17 or later before upgrading to this CloudBees CI release.

Removed `ingress-nginx` subchart support

The use of the `ingress-nginx` subchart in the CloudBees CI chart was previously deprecated and is now no longer supported. If you are using the `ingress-nginx` subchart, you must migrate to the official `ingress-nginx` chart prior to upgrading CloudBees CI on modern cloud platforms. For migration instructions, refer to [Migrate from the ingress-nginx subchart in CloudBees CI](/d/kb-1762465645).

### Modern cloud platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms/2.528.2.34846) [Plugins list - Managed controller](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-managed-controller/2.528.2.34846) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-operations-center/2.528.2.34846)

### Traditional platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/traditional-platforms/2.528.2.34846) [Plugins list - Client controller](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-client-controller/2.528.2.34846) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-operations-center/2.528.2.34846)

2.528.1.29795 Security release
------------------------------

Released: October 29, 2025

### Modern cloud platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms/2.528.1.29795) [Plugins list - Managed controller](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-managed-controller/2.528.1.29795) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-operations-center/2.528.1.29795)

### Traditional platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/traditional-platforms/2.528.1.29795) [Plugins list - Client controller](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-client-controller/2.528.1.29795) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-operations-center/2.528.1.29795)

2.528.1.29783 Security release
------------------------------

Released: October 15, 2025

Controller authentication mapping is now enforced for List/Move/Copy/Promote remote operations

When using cross-controller List/Move/Copy/Promote, source controller authentication mapping is now verified before performing the operation.

### Modern cloud platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms/2.528.1.29783) [Plugins list - Managed controller](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-managed-controller/2.528.1.29783) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-operations-center/2.528.1.29783)

### Traditional platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/traditional-platforms/2.528.1.29783) [Plugins list - Client controller](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-client-controller/2.528.1.29783) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-operations-center/2.528.1.29783)

2.516.3.29358 Security release
------------------------------

Released: September 17, 2025

Lack of audience check on machine-to-machine authentication

Machine-to-machine authentication is used within the CloudBees CI cluster to enable communication between controllers or the operations center with standalone micro services (and services to controllers). Previously, the token audience was not being checked, which could have allowed a rogue service (or controller) to impersonate other services in the cluster. Now, an audience check to the authentication process has been added.

This fix requires a controller re-provisioning to ensure all Kubernetes resources are properly generated.

### Modern cloud platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms/2.516.3.29358) [Plugins list - Managed controller](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-managed-controller/2.516.3.29358) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/modern-cloud-platforms-operations-center/2.516.3.29358)

### Traditional platforms

[Full release notes](/docs/release-notes/latest/cloudbees-ci/traditional-platforms/2.516.3.29358) [Plugins list - Client controller](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-client-controller/2.516.3.29358) [Plugins list - Operations center](/docs/release-notes/latest/cloudbees-ci/traditional-platforms-operations-center/2.516.3.29358)