LIVE · cybersecurity feed
Live wire
vendor2 exploited in the wild

Jfrog

14 CVEs published in the last four months and 3 stories. Exploited flaws first.

Critical1
High12
Medium1
Exploited (KEV)2

Patch these first

CVECVSSSeverityProductSummaryPublished
CVE-2026-82329exploited9.8criticalartifactoryJFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthentica8d ago
CVE-2026-66384exploited5.3mediumartifactoryAn authenticated user may write data outside the intended Docker cache path under specific remote-repository condi24d ago

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-82329exploited9.8criticalartifactoryJFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthentica8d ago
CVE-2026-659218.8highartifactoryA path validation weakness in archive extraction/write handling allows entries with traversal sequences to be writ40d ago
CVE-2026-660148.8highartifactoryJFrog Artifactory contains an authentication handling weakness in internal request processing that, under specific40d ago
CVE-2026-420178.8highartifactoryAn event-handling weakness in JFrog Artifactory could expose privileged authorization material to a lower-privileg40d ago
CVE-2026-656168.8highartifactoryIncorrect authorization validation in refresh token signature allows non-admin users to obtain a signed JFrog admi40d ago
CVE-2026-656178.8highartifactoryA deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confi40d ago
CVE-2026-663758.1highartifactoryA low-privilege authenticated user may permanently remove protected internal metadata across repositories under sp24d ago
CVE-2026-420168.1highartifactoryJFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a 40d ago
CVE-2026-687577.5highartifactoryA user with access to a valid SAML response may impersonate another user under specific conditions.24d ago
CVE-2026-660157.2highartifactoryAn authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under admin-provisioned acc40d ago
CVE-2026-687527.2highartifactoryA Project Resource Manager may gain broader administrative privileges under specific conditions.24d ago
CVE-2026-687597.2highartifactoryA holder of a valid integration credential may impersonate other users under specific conditions.24d ago
CVE-2026-659227.1highartifactoryAn authorization weakness in JFrog Artifactory internal metadata handling could allow a user with limited reposito40d ago
CVE-2026-66384exploited5.3mediumartifactoryAn authenticated user may write data outside the intended Docker cache path under specific remote-repository condi24d ago

Filter the full tracker by Jfrog

Our coverage of Jfrog

CVE-2026-82329critical

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to administrative access in Artifactory. "JFrog Artifactory contains an authentication weakness that, under default

CVE-2026-82329critical

Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild

Exploitation of the authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure. The post Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild appeared first on SecurityWeek.

vulnerability

JFrog Artifactory Flaws Enable Software Supply Chain Attacks

Two Artifactory flaws allowed attackers to poison package metadata across software repositories