Find notable cyber news and cases, enriched with sources, timelines, and signals.

JFrog Artifactory security fixes (multiple vulnerabilities)

Security Patch Release
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

JFrog released fixes for Artifactory after a zero-day in self-hosted deployments came to light, reducing exposure for cloud and self-hosted customers. The vendor said cloud customers are already protected, and self-hosted operators should move to the remediating build for their maintained branch. Several Artifactory CVE records were also published on July 27, but the exact mapping to the exploited flaw remains unclear.

Related Happenings

TeamPCP Cloud stealer credential-stealing operation

Malware Activity
H score53 First: 24.03.2026 11:29 Last: 24.03.2026 11:29 Sources 1

About this happening: TeamPCP Cloud stealer was used in poisoned GitHub Actions and extension payloads that hit Checkmarx workflows, expanding a supply-chain credential-theft operation acro...

Latest development: 23.04.2026 22:21

Threat actors published a malicious @bitwarden/cli version 2026.4.0 on April 22, 2026, likely through a compromised GitHub Action in Bitwarden's CI/CD pipeline, and used bw_setup.js and bw1.js to download Bun, steal developer secrets, and exfiltrate AES-256-GCM-encrypted data through public GitHub repositories under victim accounts.

Timeline

  1. 28.07.2026 16:33 2 articles · 2h ago

    JFrog releases Artifactory fixes for cloud and self-hosted customers

    Mitigation Patch Update

    JFrog confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment, then developed and released fixes for cloud and self-hosted customers. JFrog said cloud customers are already protected, and self-hosted users should review the Artifactory release notes and move to the remediating build for their maintained branch; several Artifactory CVE records were published on July 27, but the mapping to the exploited flaw remains unresolved.

    Show sources