CVE-2026-66384
Summary
CVE-2026-66384 is a security vulnerability affecting JFrog Artifactory, the widely used binary repository manager for software development and CI/CD pipelines. It was described by CISA as "improperly limited" in scope of its technical classification, but it has been confirmed to be under active exploitation in the wild.
Timeline
CISA added CVE-2026-66384 to its Known Exploited Vulnerabilities (KEV) Catalog on 27 August 2026 on the basis of evidence of active exploitation. Federal agencies in the United States were directed to remediate under Binding Operational Directive (BOD) timelines and to check for pre-patch compromise.
Technical detail
Being an artifact stored in JFrog Artifactory, the vulnerability affects a core piece of infrastructure used to store, manage and distribute software binaries and packages. An "improperly limited" flaw of this kind typically allows an unauthenticated or low-privileged attacker to perform actions the vendor intended to restrict โ in this case, likely interferes with access, integrity or availability controls within the repository manager. Because Artifactory frequently sits at the heart of an organisation's software supply chain, a compromise of this component can have downstream trust implications for everything that consumes artifacts from it.
Significance
The placement of this vulnerability on the KEV Catalog reflects confirmed active exploitation rather than merely theoretical risk. JFrog Artifactory instances are commonly internet-exposed to support remote development and package distribution, which raises the practical attack surface. Federal agencies in the US, and any organisation operating JFrog Artifactory, should treat this as a priority remediation item.
AU/NZ relevance
JFrog Artifactory is deployed across Australian and New Zealand enterprises and government suppliers as part of standard software engineering pipelines. Australian and New Zealand SOCs and DevSecOps teams should confirm whether their Artifactory instances are patched within the CISA-recommended timelines and review for any indicators of pre-patch compromise.