ZoomEye finds 1,538 Jenkins, 169 Harbor and 32 SonarQube exposed online
A ZoomEye scan collected on 22 September 2026 found 1,538 Jenkins servers, 169 Harbor registries and 32 SonarQube instances reachable from the internet. These build-chain tools hold deployment credentials, so public exposure risks leaking source code and secrets.
- 1,538 Jenkins, 169 Harbor and 32 SonarQube instances exposed online per ZoomEye
- For scale: Portainer at 943,412 and Grafana at 603,672 instances
- CI servers hold repo tokens, signing keys and cloud deployment credentials
- Recommended: VPN, changed default credentials, disabled anonymous access
Read next
Security