CVE-2026-66384: JFrog Artifactory Path Traversal Added to CISA KEV
ID: 0451d567-f508-5aa9-ab4d-a37bc9248100
STIX ID: report--0451d567-f508-5aa9-ab4d-a37bc9248100
Feed Name: CosmicBytez Labs
Threat Score
**CVE-2026-66384:** A path traversal vulnerability in self-hosted JFrog Artifactory allows authenticated low-privilege users to write files outside intended Docker cache paths, potentially enabling supply-chain or host compromise; CISA added it to the KEV catalog on Aug 27, 2026 confirming active exploitation, and JFrog published fixed releases (upgrade to 7.161.19 or 7.146.36) with recommended audits, permission tightening, and detection checks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
