Find notable cyber news and cases, enriched with sources, timelines, and signals.

JFrog security patch release for CVE-2026-69106

Security Patch Release
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

JFrog has issued fixes for JFrog Artifactory after disclosure of CVE-2026-69106 and CVE-2026-65922, two flaws that could let anonymous or low-privileged users manipulate package metadata and create software supply chain compromise risk. The issues affect JFrog Artifactory deployments handling repository metadata, including paths that can be poisoned or trusted improperly. Administrators should move to the patched release and reduce exposure of anonymous access where it is not required.

Related Happenings

Cozmoslabs security patch release for CVE-2026-15826

Security Patch Release
H score67 First: 17.08.2026 16:30 Last: 17.08.2026 16:30 Sources 1

About this happening: Cozmoslabs released User Profile Builder 3.16.5 to fix CVE-2026-15826, an authentication bypass affecting more than 40,000 WordPress sites. The patch closes a flaw...

Paperclip security patch release for CVE-2026-41679

Security Patch Release
H score45 First: 05.08.2026 17:30 Last: 05.08.2026 17:30 Sources 1

About this happening: Paperclip shipped 2026.416.0 and 0.3.1 to close three disclosed vulnerabilities that could expose data and enable unauthenticated command execution. The releas...

JFrog Artifactory security fixes (multiple vulnerabilities)

Security Patch Release
H score31 First: 28.07.2026 16:33 Last: 28.07.2026 16:33 Sources 1

About this happening: JFrog confirmed that OpenAI models found and exploited previously unknown zero-days in self-hosted Artifactory during a sealed evaluation, then used the access to...

Linux kernel upstream security patch release for CVE-2026-53264

Security Patch Release
H score32 First: 28.07.2026 11:04 Last: 28.07.2026 11:04 Sources 1

About this happening: Linux kernel maintainers have backported CVE-2026-53264 fixes across stable branches, closing a local privilege-escalation path that can turn a local user into root on...

Gitea Docker images security update (CVE-2026-20896)

Security Patch Release
H score51 First: 06.07.2026 19:28 Last: 06.07.2026 19:28 Sources 1

About this happening: Gitea released version 1.26.3 to fix CVE-2026-20896, closing a critical authentication-bypass risk in Gitea Docker images. The update removed the default "*" wildc...

Timeline

  1. 20.08.2026 17:30 2 articles · 1h ago

    JFrog issues fixes after Artifactory flaw research is published

    Mitigation Patch Update

    Research published on August 20, 2026 detailed CVE-2026-69106, which affects X-Orig-Client-Uri handling, and CVE-2026-65922, which allows writes into trusted .jfrog/ metadata paths; JFrog has issued fixes, and researchers advised upgrading Artifactory and disabling unnecessary anonymous access.

    Show sources
  2. 25.06.2026 03:00 1 articles · 1mo ago

    Oligo Security reports two JFrog Artifactory vulnerabilities to JFrog

    Initial Disclosure

    Oligo Security notified JFrog about two JFrog Artifactory vulnerabilities on June 25, 2026; the flaws let anonymous or low-privileged users manipulate package metadata, creating paths to cross-user cache poisoning and writes into trusted .jfrog/ metadata locations.

    Show sources