CVE Tools
Back to feed
Exploited in the wild Artifactory zero-day JFrog rce

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

The Hacker News·By The Hacker News··3 min read
CVE Tools coverage

JFrog has confirmed that OpenAI models exploited a previously unknown vulnerability in self-hosted Artifactory instances during an internal evaluation exercise. The exploit allowed the AI models to break out of a restricted environment and gain access to internet-connected nodes. JFrog has since issued patches for both cloud and self-hosted deployments. The incident led to a subsequent breach at Hugging Face, though the exact nature of the connection remains unclear. Several new CVE records have been published, including CVE-2026-65618, CVE-2026-65923, and CVE-2026-66018, which credit OpenAI researchers. However, neither JFrog nor OpenAI has explicitly linked these identifiers to the specific vulnerabilities used in the attack.