VENDOR
JFrog vulnerabilities: CVEs, exploitation and patches
Every JFrog CVE reviewed by Diras Labs analysts, newest first, with exploitation status and fixes.
-
CVE-2026-42016
Artifactory incorrect authorization privilege escalationHIGH 8.8
- CISA KEV
- EXPLOITED
- PATCH AVAILABLE
-
CVE-2026-42018
Artifactory improper authentication returns internal anonymous tokenHIGH 7.5
- CISA KEV
- EXPLOITED
- PATCH AVAILABLE
-
CVE-2026-82329
Artifactory authentication weakness allows pre-auth admin takeoverCRITICAL 9.8
- CISA KEV
- EXPLOITED
- PoC PUBLIC
- PATCH AVAILABLE
No CVEs on this page match the filters.
3 CVEs · page 1 of 1