SYS::ONLINE
Wasteland.
Briefs2300
Issues25
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-66384 2026-08-27

CVE-2026-66384: JFrog Artifactory Path Traversal Added to CISA KEV

"The editorial note is cut off mid-sentence ("...(https://openai.com/index/hugging-face-incident-and") so I can't tell what it asked for that source. I've applied the one change that's consistent with both the fragment…"

The editorial note is cut off mid-sentence ("...(https://openai.com/index/hugging-face-incident-and") so I can't tell what it asked for that source. I've applied the one change that's consistent with both the fragment and your "keep every source URL" constraint; keeping the link but marking it explicitly as unverified and load-bearing on nothing. Tell me what the rest of the note said and I'll redo it.


CVE-2026-66384: JFrog Artifactory Path Traversal Added to CISA KEV

CISA added CVE-2026-66384, a path traversal flaw in JFrog Artifactory, to its Known Exploited Vulnerabilities catalog on 2026-08-27 with a remediation deadline of 2026-09-10.

What Is It

CVE-2026-66384 is an improper limitation of a pathname to a restricted directory vulnerability (CWE-22) in JFrog Artifactory. Under specific remote-repository conditions, an authenticated user may write data outside the intended Docker cache path.

JFrog scored the issue CVSS 3.1 base 5.3 (MEDIUM), vector CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N, network-reachable, high attack complexity, low privileges required, no user interaction, with high integrity impact and no confidentiality or availability impact.

Why It Matters

CISA's SSVC assessment for this CVE records exploitation as active, automatable as no, and technical impact as partial. Its presence in the KEV catalog confirms exploitation in the wild despite the medium CVSS score. Known ransomware campaign use is listed as Unknown.

The impact profile is integrity-only: an authenticated actor writing files outside the Docker cache boundary in an artifact repository. In a build system, that boundary matters more than the base score suggests; a repository that serves cached images to downstream pipelines is a distribution point, and unauthorized writes to it propagate.

What's Vulnerable

JFrog Artifactory, per the vendor-supplied version ranges:

Matching CPE: cpe:2.3:a:jfrog:artifactory:*:*:*:*:*:-:*:*.

Patch Status

Fixed releases are 7.146.35 and 7.161.16 per the affected-version boundaries. CISA's required action: apply mitigations in accordance with vendor instructions, ensuring compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's "Forensics Triage Requirements." Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines. Due date: 2026-09-10.

Sources