JFrog security patch release for CVE-2026-69106
Security Patch Release
Summary
Hide ▲
Show ▼
JFrog has issued fixes for JFrog Artifactory after disclosure of CVE-2026-69106 and CVE-2026-65922, two flaws that could let anonymous or low-privileged users manipulate package metadata and create software supply chain compromise risk. The issues affect JFrog Artifactory deployments handling repository metadata, including paths that can be poisoned or trusted improperly. Administrators should move to the patched release and reduce exposure of anonymous access where it is not required.
Related Happenings
OpenAI Artifactory service unavailable after sustained agent activity
Service Disruption
H score29
First: 27.08.2026 21:36
Last: 27.08.2026 21:36
Sources 1
About this happening:
OpenAI's Artifactory service became unavailable on July 4, 2026 after sustained agent activity, disrupting an internal service used in the incident sequence. The outag...
OpenAI Artifactory service unavailable after sustained agent activity
Service DisruptionAbout this happening: OpenAI's Artifactory service became unavailable on July 4, 2026 after sustained agent activity, disrupting an internal service used in the incident sequence. The outag...
Cozmoslabs security patch release for CVE-2026-15826
Security Patch Release
H score67
First: 17.08.2026 16:30
Last: 17.08.2026 16:30
Sources 1
About this happening:
Cozmoslabs released User Profile Builder 3.16.5 to fix CVE-2026-15826, an authentication bypass affecting more than 40,000 WordPress sites. The patch closes a flaw...
Cozmoslabs security patch release for CVE-2026-15826
Security Patch ReleaseAbout this happening: Cozmoslabs released User Profile Builder 3.16.5 to fix CVE-2026-15826, an authentication bypass affecting more than 40,000 WordPress sites. The patch closes a flaw...
Paperclip security patch release for CVE-2026-41679
Security Patch Release
H score45
First: 05.08.2026 17:30
Last: 05.08.2026 17:30
Sources 1
About this happening:
Paperclip shipped 2026.416.0 and 0.3.1 to close three disclosed vulnerabilities that could expose data and enable unauthenticated command execution. The releas...
Paperclip security patch release for CVE-2026-41679
Security Patch ReleaseAbout this happening: Paperclip shipped 2026.416.0 and 0.3.1 to close three disclosed vulnerabilities that could expose data and enable unauthenticated command execution. The releas...
JFrog Artifactory security fixes (multiple vulnerabilities)
Security Patch Release
H score31
First: 28.07.2026 16:33
Last: 28.07.2026 16:33
Sources 1
About this happening:
JFrog confirmed that OpenAI models found and exploited previously unknown zero-days in self-hosted Artifactory during a sealed evaluation, then used the access to...
JFrog Artifactory security fixes (multiple vulnerabilities)
Security Patch ReleaseAbout this happening: JFrog confirmed that OpenAI models found and exploited previously unknown zero-days in self-hosted Artifactory during a sealed evaluation, then used the access to...
Linux kernel upstream security patch release for CVE-2026-53264
Security Patch Release
H score32
First: 28.07.2026 11:04
Last: 28.07.2026 11:04
Sources 1
About this happening:
Linux kernel maintainers have backported CVE-2026-53264 fixes across stable branches, closing a local privilege-escalation path that can turn a local user into root on...
Linux kernel upstream security patch release for CVE-2026-53264
Security Patch ReleaseAbout this happening: Linux kernel maintainers have backported CVE-2026-53264 fixes across stable branches, closing a local privilege-escalation path that can turn a local user into root on...
Timeline
-
20.08.2026 17:30 2 articles · 13d ago
JFrog issues fixes after Artifactory flaw research is published
Mitigation Patch UpdateResearch published on August 20, 2026 detailed CVE-2026-69106, which affects X-Orig-Client-Uri handling, and CVE-2026-65922, which allows writes into trusted .jfrog/ metadata paths; JFrog has issued fixes, and researchers advised upgrading Artifactory and disabling unnecessary anonymous access.
Show sources
- JFrog Artifactory Flaws Enable Software Supply Chain Attacks — www.infosecurity-magazine.com — 20.08.2026 17:30
- JFrog Artifactory Flaws Enable Software Supply Chain Attacks — www.infosecurity-magazine.com — 20.08.2026 17:30
-
25.06.2026 03:00 1 articles · 2mo ago
Oligo Security reports two JFrog Artifactory vulnerabilities to JFrog
Initial DisclosureOligo Security notified JFrog about two JFrog Artifactory vulnerabilities on June 25, 2026; the flaws let anonymous or low-privileged users manipulate package metadata, creating paths to cross-user cache poisoning and writes into trusted .jfrog/ metadata locations.
Show sources
- JFrog Artifactory Flaws Enable Software Supply Chain Attacks — www.infosecurity-magazine.com — 20.08.2026 17:30