CVE-2026-66384: listed in the CISA KEV catalog
CVE-2026-66384 · CVSS 5.3 MEDIUM · KEV 2026-08-27 · patch available
An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.
Is CVE-2026-66384 exploited?
- Listed in the CISA KEV catalog on 2026-08-27.
- Federal remediation due 2026-09-10.
- Public exploit code: none found in monitored sources.
Which products and versions are affected?
- JFrog · Artifactory · SaaS <7.164.0
- JFrog · Artifactory · Self-Managed <7.161.16
Is there a patch?
- Artifactory SaaS 7.164.0
- Artifactory Self-Managed 7.161.16
What PlainSec published about CVE-2026-66384
Primary sources
What this record does not say
KEV and EPSS are re-checked daily. Record last updated 2026-08-28.