JFrog vendor intelligence
JFrog Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting JFrog products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 5
- Known exploited vulnerabilities affecting JFrog products
- In CISA KEV
- 2
- Records also listed in the official catalog
- Beyond CISA KEV
- 3
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 0
- JFrog KEVs with sensor-observed exploitation activity
The catalog gap matters for JFrog exposure
Three of the five exploited JFrog vulnerabilities tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 60% of this vendor portfolio.
- 40%
- Covered by CISA
- 60%
- Beyond CISA
- 2
- Product families
Attested JFrog vulnerabilities
5 known exploited vulnerabilities in this exploited-vulnerability portfolio. Search, then narrow it to official CISA coverage or the additional records Previdian tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-42018
Anonymous user token generation exposure in JFrog Artifactory |
artifactory | High | Beyond CISA | 10 Sep 2026 |
|
CVE-2026-42016
Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation |
artifactory | High | Beyond CISA | 10 Sep 2026 |
|
CVE-2026-82329
Potential authentication bypass leading to administrative access in Artifactory |
artifactory | Confirmed | In CISA | 01 Sep 2026 |
|
CVE-2026-66384
Authenticated users may write data outside the intended Docker cache path |
artifactory | Confirmed | In CISA | 27 Aug 2026 |
|
CVE-2019-9733
An issue was discovered in JFrog Artifactory 6.7.3. By default, the access-admin account is used to reset the password of the admin account in case... |
Artifactory | High | Beyond CISA | 28 Jun 2025 |
No JFrog vulnerabilities match this search or filter.
Showing 5 of 5 on this page (5 JFrog known exploited vulnerabilities).
Recurring weakness patterns
Authentication, limitation, and incorrect authorization account for four mapped occurrences across this JFrog KEV portfolio.