JFrog Product Security Update Advisory (CVE-2026-66384)

JFrog Product Security Update Advisory (CVE-2026-66384)
  • A security update addressing a vulnerability in JFrog products has been released.
  • The affected product is JFrog Artifactory.
  • The vulnerability is identified as CVE-2026-66384 and is a write-to-external-data vulnerability in the Docker path of JFrog Artifactory.
  • Affected Versions are JFrog Artifactory versions prior to 7.146.35 And versions from 7.161.0 Through 7.161.16.
  • The fixed versions are JFrog Artifactory 7.146.35 And 7.161.16.
  • JFrog recommends updating to the latest version with the Vulnerability Patch as instructed on the reference site.
  • The reference site is JFrog Security Advisories.