CISA Adds JFrog Artifactory Vulnerability to Actively Exploited Vulnerabilities Catalog

On August 27, 2026, CISA added CVE-2026-66384 in JFrog Artifactory to the KEV catalog. Operators of self-hosted instances should verify their version and deploy available patches.

CISA KEV JFrog Artifactory: On August 27, 2026, CISA added the CVE-2026-66384 vulnerability in JFrog Artifactory to the Known Exploited Vulnerabilities (KEV) catalog. This means it has evidence that the vulnerability is being exploited in the wild. The issue affects self-hosted Artifactory instances, and the vendor has already released fixes.

CVE-2026-66384 is a CWE-22 vulnerability, meaning a file path access issue. Under specific remote Docker repository configuration conditions, it could allow an authenticated user to write outside the designated Docker cache path. Successful exploitation could therefore compromise the integrity of data stored in the system.

CISA KEV JFrog Artifactory: Which Versions Are Affected

According to JFrog’s security advisory, the issue affects self-hosted Artifactory branches older than 7.146.35, as well as versions from 7.161.0 through the release before 7.161.16. The vendor fixed the vulnerability in versions 7.146.35 and 7.161.16.

  • Branches older than 7.146.35 should be upgraded to at least 7.146.35.
  • Installations in the 7.161.x branch affected through version 7.161.15 should be upgraded to 7.161.16 or a newer fixed release.
  • For JFrog Cloud, the vendor says it has already hardened the affected environments and customers should not take action themselves.

Based on the available description, the risk primarily concerns unpatched locally operated instances with the relevant remote Docker repository configuration. This is not a scenario requiring no access: an attacker needs authenticated access to Artifactory. However, inclusion in KEV confirms that this is not merely a theoretically described flaw.

What Operators Should Do

Operators of self-hosted Artifactory should immediately determine the version in use and compare it with the ranges listed by the vendor. If they use an affected release, they should deploy the applicable fix from JFrog. For instances with remote Docker repositories configured, it is advisable to prioritize reviewing the configuration and authenticated-user access.

For entries in the KEV catalog, CISA recommends following the vendor’s mitigations. In this case, updates are available, so remediation does not depend solely on temporary restrictions or configuration changes.

Attack Details Are Not Publicly Available

CISA and JFrog have not yet publicly described the scope of the observed attacks, the actors’ identities, the victims, or the specific exploitation chain. It is also not confirmed whether attackers are targeting a particular type of Artifactory configuration or what the scope of activity is outside environments subject to CISA.

Further information could come from potential technical indicators from CISA, additional detection procedures from JFrog, or security-team announcements about incidents related to Artifactory and remote Docker repositories.

Sources

Verified and updated: 08/27/2026 20:30

Sharing