VENDOR

JFrog vulnerabilities: CVEs, exploitation and patches

Every JFrog CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.

  1. CVE-2026-42016
    Artifactory incorrect authorization privilege escalation JFrog Artifactory ·
    • CISA KEV
    • EXPLOITED
    • PATCH AVAILABLE
    HIGH 8.8
  2. CVE-2026-42018
    Artifactory improper authentication returns internal anonymous token JFrog Artifactory ·
    • CISA KEV
    • EXPLOITED
    • PATCH AVAILABLE
    HIGH 7.5
  3. CVE-2026-82329
    Artifactory authentication weakness allows pre-auth admin takeover JFrog Artifactory ·
    • CISA KEV
    • EXPLOITED
    • PoC PUBLIC
    • PATCH AVAILABLE
    CRITICAL 9.8
3 CVEs · page 1 of 1