logo

CVE-2026-66384: JFrog Artifactory Path Traversal Added to CISA KEV

ID: 0451d567-f508-5aa9-ab4d-a37bc9248100

STIX ID: report--0451d567-f508-5aa9-ab4d-a37bc9248100

Feed Name: CosmicBytez Labs

Threat Score
70/100

Date Published: 2026-08-28

Date Updated: 2026-08-28

...
...

**CVE-2026-66384:** A path traversal vulnerability in self-hosted JFrog Artifactory allows authenticated low-privilege users to write files outside intended Docker cache paths, potentially enabling supply-chain or host compromise; CISA added it to the KEV catalog on Aug 27, 2026 confirming active exploitation, and JFrog published fixed releases (upgrade to 7.161.19 or 7.146.36) with recommended audits, permission tightening, and detection checks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.