CVE-2026-65618: exploitation status and patch state
CVE-2026-65618 · CVSS 6.5 MEDIUM · EPSS <1%
Improper URL validation when handling specific URLs, allows an attacker, under certain conditions, to make unauthorized requests from JFrog Artifactory, potentially exposing internal services and cached response data.
Is CVE-2026-65618 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at <1%.
Public exploit code: none found in monitored sources.