[NEW] [high] JFrog Artifactory: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in JFrog Artifactory to execute arbitrary code, escalate privileges, disclose information, manipulate files, and bypass security precautions.
CSIRTS triage
- What
- Multiple vulnerabilities in JFrog Artifactory can lead to arbitrary code execution, privilege escalation, and information disclosure.
- Who is affected
- Attackers can exploit these vulnerabilities in JFrog Artifactory installations.
- Urgency
- This is a high urgency issue as it poses serious risks to application security and data integrity.
- Action
- Users should update JFrog Artifactory to the latest version to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Artifactory
Get an email when a new Artifactory advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2548
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-420160.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all scored CVEs.
- Low exploitation riskCVE-2026-420170.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all scored CVEs.
- Low exploitation riskCVE-2026-656160.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all scored CVEs.
- Low exploitation riskCVE-2026-656170.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all scored CVEs.
- Low exploitation riskCVE-2026-656180.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all scored CVEs.
- Low exploitation riskCVE-2026-659210.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all scored CVEs.
- Low exploitation riskCVE-2026-659220.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all scored CVEs.
- Low exploitation riskCVE-2026-659230.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 9% of all scored CVEs.
- Low exploitation riskCVE-2026-659240.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all scored CVEs.
- Low exploitation riskCVE-2026-659250.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-42016 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-42017 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65616 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65617 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65618 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65921 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65922 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65923 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65924 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65925 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66014 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66015 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-66018 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactoryncsc-nl
- mediumCVE-2026-66018: Build readers can access another repository's environment properties. A caller with read acces…nvd
- highCVE-2026-66015: An authenticated privilege-escalation vulnerability in JFrog Platform may be exploited under a…nvd
- highCVE-2026-66014: JFrog Artifactory contains an authentication handling weakness in internal request processing …nvd
- mediumCVE-2026-65925: A user with JFrog Artifactory Cargo remote repository read access could make Artifactory reque…nvd
- mediumCVE-2026-65924: JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Ser…nvd
- mediumCVE-2026-65923: A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user,…nvd
- highCVE-2026-65922: An authorization weakness in JFrog Artifactory internal metadata handling could allow a user w…nvd
- highCVE-2026-65921: A path validation weakness in archive extraction/write handling allows entries with traversal …nvd
- mediumCVE-2026-65618: Improper URL validation when handling specific URLs, allows an attacker, under certain conditi…nvd
- highCVE-2026-65617: A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged …nvd
- highCVE-2026-65616: Incorrect authorization validation in refresh token signature allows non-admin users to obtain…nvd
Recent advisories for JFrog Artifactory
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownNCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactoryncsc-nl · 2026-07-31
- highCVE-2026-66014: JFrog Artifactory contains an authentication handling weakness in internal request processing …nvd · 2026-07-27
- mediumCVE-2026-65925: A user with JFrog Artifactory Cargo remote repository read access could make Artifactory reque…nvd · 2026-07-27
- mediumCVE-2026-65924: JFrog Artifactory support for Terraform remote repositories was found to be susceptible to Ser…nvd · 2026-07-27
- mediumCVE-2026-65923: A URL validation weakness in JFrog Artifactory Ansible repository handling could allow a user,…nvd · 2026-07-27
- highCVE-2026-65922: An authorization weakness in JFrog Artifactory internal metadata handling could allow a user w…nvd · 2026-07-27
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel (ntfs3): Vulnerability allows information disclosure2026-07-31