Vulnerabilities & Exploits · Web App Attack
Artifactory Fix Set Grows, But The Breach Path Is Still Unclear The real issue is still the trust boundary inside Artifactory, not one isolated bug. NCSC’s new advisory widens the fixed set to 13 CVEs, which points to broken auth and request-validation plumbing across the same release line rather than a single flaw that explains the incident.
The patched issues include token-scope checks, weak refresh-token validation, SSRF, deserialization, path traversal, and authorization failures. That spread matches the earlier picture: a repository service that could trust too much, let low-privileged users cross into higher privilege, and reach places it should not have been able to reach.
For teams using Artifactory as a control point for builds, credentials, or internal service access, the unresolved question matters. Patching is still necessary, but the wider fix set means the safe assumption is a broader repository-layer trust failure until the exploited path is pinned down.
5 sources · Jul 31
CVEs in this update
13 CVEs
Across Artifactory.
0 critical · 8 high · 5 medium · 0 low
1 in CISA KEV · 1 with EPSS above 1%
Highest severity: CVE-2026-65617 · 8.8 HIGH
Highest EPSS: CVE-2026-42016 · 8.6%
Showing the top 10 by KEV, EPSS, and severity.
Timeline Sources Jul 31 NCSC-NL Advisories
Kwetsbaarheden verholpen in JFrog Artifactory
JFrog heeft meerdere kwetsbaarheden verholpen in JFrog Artifactory De kwetsbaarheden betreffen verschillende onderdelen van JFrog Artifactory.
original Jul 29 SecurityWeek
JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack
The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given.
original Jul 28 Ars Technica Security
JFrog tries to spin OpenAI 0-day exploit of its app into a success story
10 days passed from OpenAI models exploiting JFrog Artifactory 0-day to release of a patch.
original Part of the PlainSec briefing for 2026-07-28
Every edition of this story: Artifactory Fix Set Grows, But The Breach Path Is Still Unclear
More from today
Vulnerabilities & Exploits · Web App Attack
Artifactory Fix Set Grows, But The Breach Path Is Still Unclear The real issue is still the trust boundary inside Artifactory, not one isolated bug. NCSC’s new advisory widens the fixed set to 13 CVEs, which points to broken auth and request-validation plumbing across the same release line rather than a single flaw that explains the incident.
The patched issues include token-scope checks, weak refresh-token validation, SSRF, deserialization, path traversal, and authorization failures. That spread matches the earlier picture: a repository service that could trust too much, let low-privileged users cross into higher privilege, and reach places it should not have been able to reach.
For teams using Artifactory as a control point for builds, credentials, or internal service access, the unresolved question matters. Patching is still necessary, but the wider fix set means the safe assumption is a broader repository-layer trust failure until the exploited path is pinned down.
5 sources · Jul 31
CVEs in this update
13 CVEs
Across Artifactory.
0 critical · 8 high · 5 medium · 0 low
1 in CISA KEV · 1 with EPSS above 1%
Highest severity: CVE-2026-65617 · 8.8 HIGH
Highest EPSS: CVE-2026-42016 · 8.6%
Showing the top 10 by KEV, EPSS, and severity.
Timeline Sources Jul 31 NCSC-NL Advisories
Kwetsbaarheden verholpen in JFrog Artifactory
JFrog heeft meerdere kwetsbaarheden verholpen in JFrog Artifactory De kwetsbaarheden betreffen verschillende onderdelen van JFrog Artifactory.
original Jul 29 SecurityWeek
JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack
The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given.
original Jul 28 Ars Technica Security
JFrog tries to spin OpenAI 0-day exploit of its app into a success story
10 days passed from OpenAI models exploiting JFrog Artifactory 0-day to release of a patch.
original Part of the PlainSec briefing for 2026-07-28
Every edition of this story: Artifactory Fix Set Grows, But The Breach Path Is Still Unclear
More from today