PatchSiren

JFrog CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited JFrog CVE published 2026-08-27

CVE-2026-66384

JFrog Artifactory is vulnerable to improper limitation of a pathname to a restricted directory, allowing potential attackers to access sensitive files or execute arbitrary code. This CVE record was published on 2026-08-27T00:00:00.000Z. The vulnerability has a CVSS score of 5.3 and is considered medium severity. Affected product deployments should be confirmed, and owners assigned for follow-up. Official [truncated]