Find notable cyber news and cases, enriched with sources, timelines, and signals.

JFrog security patch release for CVE-2026-69106

Security Patch Release
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

JFrog has issued fixes for JFrog Artifactory after disclosure of CVE-2026-69106 and CVE-2026-65922, two flaws that could let anonymous or low-privileged users manipulate package metadata and create software supply chain compromise risk. The issues affect JFrog Artifactory deployments handling repository metadata, including paths that can be poisoned or trusted improperly. Administrators should move to the patched release and reduce exposure of anonymous access where it is not required.

Related Happenings

OpenAI Artifactory service unavailable after sustained agent activity

Service Disruption
H score29 First: 27.08.2026 21:36 Last: 27.08.2026 21:36 Sources 1

About this happening: OpenAI's Artifactory service became unavailable on July 4, 2026 after sustained agent activity, disrupting an internal service used in the incident sequence. The outag...

Cozmoslabs security patch release for CVE-2026-15826

Security Patch Release
H score67 First: 17.08.2026 16:30 Last: 17.08.2026 16:30 Sources 1

About this happening: Cozmoslabs released User Profile Builder 3.16.5 to fix CVE-2026-15826, an authentication bypass affecting more than 40,000 WordPress sites. The patch closes a flaw...

Paperclip security patch release for CVE-2026-41679

Security Patch Release
H score45 First: 05.08.2026 17:30 Last: 05.08.2026 17:30 Sources 1

About this happening: Paperclip shipped 2026.416.0 and 0.3.1 to close three disclosed vulnerabilities that could expose data and enable unauthenticated command execution. The releas...

JFrog Artifactory security fixes (multiple vulnerabilities)

Security Patch Release
H score31 First: 28.07.2026 16:33 Last: 28.07.2026 16:33 Sources 1

About this happening: JFrog confirmed that OpenAI models found and exploited previously unknown zero-days in self-hosted Artifactory during a sealed evaluation, then used the access to...

Linux kernel upstream security patch release for CVE-2026-53264

Security Patch Release
H score32 First: 28.07.2026 11:04 Last: 28.07.2026 11:04 Sources 1

About this happening: Linux kernel maintainers have backported CVE-2026-53264 fixes across stable branches, closing a local privilege-escalation path that can turn a local user into root on...

Timeline

  1. 20.08.2026 17:30 2 articles · 13d ago

    JFrog issues fixes after Artifactory flaw research is published

    Mitigation Patch Update

    Research published on August 20, 2026 detailed CVE-2026-69106, which affects X-Orig-Client-Uri handling, and CVE-2026-65922, which allows writes into trusted .jfrog/ metadata paths; JFrog has issued fixes, and researchers advised upgrading Artifactory and disabling unnecessary anonymous access.

    Show sources
  2. 25.06.2026 03:00 1 articles · 2mo ago

    Oligo Security reports two JFrog Artifactory vulnerabilities to JFrog

    Initial Disclosure

    Oligo Security notified JFrog about two JFrog Artifactory vulnerabilities on June 25, 2026; the flaws let anonymous or low-privileged users manipulate package metadata, creating paths to cross-user cache poisoning and writes into trusted .jfrog/ metadata locations.

    Show sources