- A security update addressing a vulnerability in JFrog products has been released.
- The affected product is JFrog Artifactory.
- The vulnerability is identified as CVE-2026-66384 and is a write-to-external-data vulnerability in the Docker path of JFrog Artifactory.
- Affected Versions are JFrog Artifactory versions prior to 7.146.35 And versions from 7.161.0 Through 7.161.16.
- The fixed versions are JFrog Artifactory 7.146.35 And 7.161.16.
- JFrog recommends updating to the latest version with the Vulnerability Patch as instructed on the reference site.
- The reference site is JFrog Security Advisories.