Vulnerabilities · 59 days ago
The real issue is still the trust boundary inside Artifactory, not one isolated bug. NCSC’s new advisory widens the fixed set to 13 CVEs, which points to broken auth and request-validation plumbing across the same release line rather than a single flaw that explains the incident.
The patched issues include token-scope checks, weak refresh-token validation, SSRF, deserialization, path traversal, and authorization failures. That spread matches the earlier picture: a repository service that could trust too much, let low-privileged users cross into higher privilege, and reach places it should not have been able to reach.
For teams using Artifactory as a control point for builds, credentials, or internal service access, the unresolved question matters. Patching is still necessary, but the wider fix set means the safe assumption is a broader repository-layer trust failure until the exploited path is pinned down.
CVEs in this update
13 CVEs
Across Artifactory.
0 critical · 8 high · 5 medium · 0 low
1 in CISA KEV · 1 with EPSS above 1%
Highest severity: CVE-2026-65617 · 8.8 HIGH
Highest EPSS: CVE-2026-42016 · 8.6%
Showing the top 10 by KEV, EPSS, and severity.
5 sources covering this story
Kwetsbaarheden verholpen in JFrog Artifactory
JFrog heeft meerdere kwetsbaarheden verholpen in JFrog Artifactory De kwetsbaarheden betreffen verschillende onderdelen van JFrog Artifactory.
JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack
The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given.
JFrog tries to spin OpenAI 0-day exploit of its app into a success story
10 days passed from OpenAI models exploiting JFrog Artifactory 0-day to release of a patch.
OpenAI models used Artifactory zero-days to escape to the internet
JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging Face.
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
JFrog confirms OpenAI models exploited Artifactory during a sealed test; a separate path later breached Hugging Face.
Part of the PlainSec briefing for 2026-07-28