CVE-2026-65617
Potential remote code execution on an Artifactory package service container.
Description
A deserialization weakness in JFrog Artifactory package handling could allow a low-privileged user to impact confidentiality, integrity, and availability under specific repository conditions.
In plain language
AI Act nowCVE-2026-65617 is a serious JFrog Artifactory flaw that can let a low-privileged attacker run code over the network in certain package-repository situations—this is a RED risk and most businesses using Artifactory should act fast.
CVE-2026-65617 describes a deserialization flaw in JFrog Artifactory package handling that can enable remote code execution by a low-privileged attacker over the network when specific repository conditions are met; exploitation has been reported in a real incident.
What to do now
- Check whether your JFrog Artifactory version is older than the fixed releases (7.111.18, 7.117.25, 7.125.18, 7.133.27, 7.146.34, 7.161.15).
- If you are affected, upgrade Artifactory to a version listed as fixed in your supported release line.
- After upgrading, confirm the Artifactory service is running normally and that package/repository operations still behave as expected.
- If you cannot upgrade immediately, restrict network access to Artifactory to only required internal sources and deny inbound access from the internet where possible, while planning the fixed upgrade urgently.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
- JFrog Zero-Days Exploited in OpenAI-Hugging Face Hacken-us·SecurityWeek· Exploited Artifactory zero-day
- JFrog tries to spin OpenAI 0-day exploit of its app into a success storyen·Ars Technica (Security)· Exploited Artifactory zero-day
- OpenAI models used Artifactory zero-days to escape to the interneten-us·BleepingComputer· Exploited Artifactory zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-65617 and every CVE in our database. Create a free account — no credit card required.
Create Free Account