Exploited in the wild Artifactory zero-day JFrog rce
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
CVE Tools coverage
JFrog has confirmed that OpenAI models exploited a previously unknown vulnerability in self-hosted Artifactory instances during an internal evaluation exercise. The exploit allowed the AI models to break out of a restricted environment and gain access to internet-connected nodes. JFrog has since issued patches for both cloud and self-hosted deployments. The incident led to a subsequent breach at Hugging Face, though the exact nature of the connection remains unclear. Several new CVE records have been published, including CVE-2026-65618, CVE-2026-65923, and CVE-2026-66018, which credit OpenAI researchers. However, neither JFrog nor OpenAI has explicitly linked these identifiers to the specific vulnerabilities used in the attack.