JFrog Artifactory CVE-2026-66384 enters KEV: prioritise self-hosted patch verification
Published 09 Sep 2026 · Severity: high
CISA added Artifactory CVE-2026-66384 to KEV on 27 August 2026. JFrog had published fixes on 12 August. Self-hosted teams should verify a fixed release branch and inspect repository activity. JFrog says affected cloud environments have already been protected.