Articles tagged JFrog
-
VulnerabilityJFrog Artifactory Path Traversal (CVE-2026-66384)
CVE-2026-66384 is a CVSS 5.3 path traversal in JFrog Artifactory affecting the Docker cache, confirmed exploited per CISA KEV.
-
VulnerabilityJFrog Artifactory Authentication Bypass (CVE-2026-82329)
CVE-2026-82329 is a CVSS 9.8 authentication flaw letting an unauthenticated attacker gain JFrog Artifactory admin rights. Added to CISA KEV Sept. 2, 2026.
-
VulnerabilityJFrog Artifactory Self-Hosted Authentication Bypass (CVE-2026-42018)
CVE-2026-42018 can leak an internal anonymous-user token to unauthenticated callers in JFrog Artifactory even when anonymous access is disabled. Added to CISA KEV Sept. 11, 2026.
-
VulnerabilityJFrog Artifactory Self-Hosted Privilege Escalation (CVE-2026-42016)
CVE-2026-42016 lets attackers escalate privileges in JFrog Artifactory via a token-scope validation gap. CISA added it to KEV Sept. 11, 2026; Wiz reports in-the-wild exploitation.